CVE-2016-5385
- EPSS 84.16%
- Published 19.07.2016 02:00:17
- Last modified 12.04.2025 10:46:40
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attacker...
CVE-2016-6174
- EPSS 19.83%
- Published 12.07.2016 19:59:09
- Last modified 12.04.2025 10:46:40
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execut...
CVE-2016-4544
- EPSS 3.94%
- Published 22.05.2016 01:59:29
- Last modified 12.04.2025 10:46:40
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly h...
CVE-2016-4543
- EPSS 4.08%
- Published 22.05.2016 01:59:28
- Last modified 12.04.2025 10:46:40
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have uns...
CVE-2016-4542
- EPSS 1.23%
- Published 22.05.2016 01:59:27
- Last modified 12.04.2025 10:46:40
The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or po...
CVE-2016-4541
- EPSS 1.43%
- Published 22.05.2016 01:59:26
- Last modified 12.04.2025 10:46:40
The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact vi...
CVE-2016-4540
- EPSS 1.46%
- Published 22.05.2016 01:59:24
- Last modified 12.04.2025 10:46:40
The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact v...
CVE-2016-4539
- EPSS 3.37%
- Published 22.05.2016 01:59:23
- Last modified 12.04.2025 10:46:40
The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other imp...
CVE-2016-4538
- EPSS 4.88%
- Published 22.05.2016 01:59:22
- Last modified 12.04.2025 10:46:40
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows rem...
CVE-2016-4537
- EPSS 4.88%
- Published 22.05.2016 01:59:21
- Last modified 12.04.2025 10:46:40
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified ot...