CVE-2015-6836
- EPSS 9.8%
- Veröffentlicht 19.01.2016 05:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "...
CVE-2015-6833
- EPSS 4.84%
- Veröffentlicht 19.01.2016 05:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled during an extr...
CVE-2015-6832
- EPSS 5.15%
- Veröffentlicht 19.01.2016 05:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to execute arbitrary code via crafted serialized data that triggers m...
CVE-2015-6831
- EPSS 7.06%
- Veröffentlicht 19.01.2016 05:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedLis...
CVE-2015-6527
- EPSS 3.86%
- Veröffentlicht 19.01.2016 05:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a crafted value in the third argument to the str_ireplace function.
CVE-2015-5590
- EPSS 4.63%
- Veröffentlicht 19.01.2016 05:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Stack-based buffer overflow in the phar_fix_filepath function in ext/phar/phar.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a l...
CVE-2016-1283
- EPSS 7.79%
- Veröffentlicht 03.01.2016 00:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgrou...
CVE-2015-7804
- EPSS 8.8%
- Veröffentlicht 11.12.2015 12:00:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (uninitialized pointer dereference and application crash) by including the / filen...
CVE-2015-7803
- EPSS 10.29%
- Veröffentlicht 11.12.2015 12:00:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a .phar file with a crafted TAR archive entry i...
CVE-2015-8394
- EPSS 4.82%
- Veröffentlicht 02.12.2015 01:59:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a ...