CVE-2016-4544
- EPSS 4.3%
- Veröffentlicht 22.05.2016 01:59:29
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly h...
CVE-2016-4543
- EPSS 5.44%
- Veröffentlicht 22.05.2016 01:59:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have uns...
CVE-2016-4542
- EPSS 1.23%
- Veröffentlicht 22.05.2016 01:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or po...
CVE-2016-4541
- EPSS 1.94%
- Veröffentlicht 22.05.2016 01:59:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact vi...
CVE-2016-4540
- EPSS 1.97%
- Veröffentlicht 22.05.2016 01:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact v...
CVE-2016-4539
- EPSS 4.51%
- Veröffentlicht 22.05.2016 01:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other imp...
CVE-2016-4538
- EPSS 6.48%
- Veröffentlicht 22.05.2016 01:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows rem...
CVE-2016-4537
- EPSS 6.48%
- Veröffentlicht 22.05.2016 01:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified ot...
CVE-2016-3674
- EPSS 2.86%
- Veröffentlicht 17.05.2016 14:08:03
- Zuletzt bearbeitet 23.05.2025 17:54:18
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbi...
CVE-2015-3152
- EPSS 52.25%
- Veröffentlicht 16.05.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade at...