CVE-2016-4544
- EPSS 6.69%
- Veröffentlicht 22.05.2016 01:59:29
- Zuletzt bearbeitet 06.05.2026 22:30:45
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly h...
CVE-2016-4543
- EPSS 12.18%
- Veröffentlicht 22.05.2016 01:59:28
- Zuletzt bearbeitet 06.05.2026 22:30:45
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have uns...
CVE-2016-4542
- EPSS 6.06%
- Veröffentlicht 22.05.2016 01:59:27
- Zuletzt bearbeitet 06.05.2026 22:30:45
The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or po...
CVE-2016-4541
- EPSS 6.23%
- Veröffentlicht 22.05.2016 01:59:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact vi...
CVE-2016-4540
- EPSS 6.23%
- Veröffentlicht 22.05.2016 01:59:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact v...
CVE-2016-4539
- EPSS 6.23%
- Veröffentlicht 22.05.2016 01:59:23
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other imp...
CVE-2016-4538
- EPSS 6.23%
- Veröffentlicht 22.05.2016 01:59:22
- Zuletzt bearbeitet 06.05.2026 22:30:45
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows rem...
CVE-2016-4537
- EPSS 5.87%
- Veröffentlicht 22.05.2016 01:59:21
- Zuletzt bearbeitet 06.05.2026 22:30:45
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified ot...
CVE-2016-4346
- EPSS 5.67%
- Veröffentlicht 22.05.2016 01:59:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
CVE-2016-4345
- EPSS 5.18%
- Veröffentlicht 22.05.2016 01:59:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based bu...