CVE-2016-7413
- EPSS 6.65%
- Veröffentlicht 17.09.2016 21:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a wddxPacket XML document...
CVE-2016-7412
- EPSS 8.85%
- Veröffentlicht 17.09.2016 21:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allows remote MySQL servers to cause a denial of service (heap-based buffer overflow) or possibly have un...
CVE-2016-7411
- EPSS 5.65%
- Veröffentlicht 17.09.2016 21:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an unserialize call that re...
CVE-2016-7134
- EPSS 4.85%
- Veröffentlicht 12.09.2016 01:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via ...
CVE-2016-7133
- EPSS 4.05%
- Veröffentlicht 12.09.2016 01:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.
CVE-2016-7132
- EPSS 8.83%
- Veröffentlicht 12.09.2016 01:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is ...
CVE-2016-7131
- EPSS 8.83%
- Veröffentlicht 12.09.2016 01:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via a malformed wddxPacket XML document that is...
CVE-2016-7130
- EPSS 6.67%
- Veröffentlicht 12.09.2016 01:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an inv...
CVE-2016-7129
- EPSS 6.84%
- Veröffentlicht 12.09.2016 01:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via an invalid ISO 8601 time value, a...
CVE-2016-7128
- EPSS 7.77%
- Veröffentlicht 12.09.2016 01:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that exceeds the file size, which allows remote attackers to obtain sensitive information from process memor...