CVE-2016-7416
- EPSS 2.26%
- Published 17.09.2016 21:59:08
- Last modified 12.04.2025 10:46:40
ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application cra...
CVE-2016-7414
- EPSS 2.03%
- Published 17.09.2016 21:59:06
- Last modified 12.04.2025 10:46:40
The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enough, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possib...
CVE-2016-7413
- EPSS 2.32%
- Published 17.09.2016 21:59:04
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a wddxPacket XML document...
CVE-2016-7412
- EPSS 1.73%
- Published 17.09.2016 21:59:03
- Last modified 12.04.2025 10:46:40
ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allows remote MySQL servers to cause a denial of service (heap-based buffer overflow) or possibly have un...
CVE-2016-7411
- EPSS 0.87%
- Published 17.09.2016 21:59:02
- Last modified 12.04.2025 10:46:40
ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an unserialize call that re...
CVE-2016-7134
- EPSS 0.52%
- Published 12.09.2016 01:59:12
- Last modified 12.04.2025 10:46:40
ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via ...
CVE-2016-7133
- EPSS 0.5%
- Published 12.09.2016 01:59:11
- Last modified 12.04.2025 10:46:40
Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.
CVE-2016-7132
- EPSS 6.38%
- Published 12.09.2016 01:59:10
- Last modified 12.04.2025 10:46:40
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is ...
CVE-2016-7131
- EPSS 6.38%
- Published 12.09.2016 01:59:09
- Last modified 12.04.2025 10:46:40
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via a malformed wddxPacket XML document that is...
CVE-2016-7130
- EPSS 2.56%
- Published 12.09.2016 01:59:08
- Last modified 12.04.2025 10:46:40
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an inv...