CVE-2016-5399
- EPSS 17.14%
- Veröffentlicht 21.04.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.
CVE-2017-7963
- EPSS 1.67%
- Veröffentlicht 19.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this, stating "Ther...
CVE-2017-6441
- EPSS 0.42%
- Veröffentlicht 03.04.2017 05:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classif...
CVE-2017-7272
- EPSS 1.11%
- Veröffentlicht 27.03.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that ...
CVE-2015-8994
- EPSS 2%
- Veröffentlicht 02.03.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x after 5.6.28 or 7.x after 7.0.13, the issue is resolved in a non-default configuration with the opcache.validate_...
CVE-2016-10158
- EPSS 4.99%
- Veröffentlicht 24.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divid...
CVE-2016-10159
- EPSS 10.26%
- Veröffentlicht 24.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PH...
CVE-2016-10160
- EPSS 4.7%
- Veröffentlicht 24.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archiv...
CVE-2016-10161
- EPSS 14.63%
- Veröffentlicht 24.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data...
CVE-2016-10162
- EPSS 4%
- Veröffentlicht 24.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacke...