Show filters
65 Total Results
Displaying 61-65 of 65
Sort by:
Attacker Value
Unknown
CVE-2016-4072
Disclosure Date: May 20, 2016 (last updated November 08, 2023)
The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c.
0
Attacker Value
Unknown
CVE-2016-4070
Disclosure Date: May 20, 2016 (last updated November 08, 2023)
Integer overflow in the php_raw_url_encode function in ext/standard/url.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to cause a denial of service (application crash) via a long string to the rawurlencode function. NOTE: the vendor says "Not sure if this qualifies as security issue (probably not).
0
Attacker Value
Unknown
CVE-2015-8865
Disclosure Date: May 20, 2016 (last updated November 08, 2023)
The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5, mishandles continuation-level jumps, which allows context-dependent attackers to cause a denial of service (buffer overflow and application crash) or possibly execute arbitrary code via a crafted magic file.
0
Attacker Value
Unknown
CVE-2016-3185
Disclosure Date: May 16, 2016 (last updated November 08, 2023)
The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (type confusion and application crash) via crafted serialized _cookies data, related to the SoapClient::__call method in ext/soap/soap.c.
0
Attacker Value
Unknown
CVE-2016-2554
Disclosure Date: May 16, 2016 (last updated November 25, 2024)
Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TAR archive.
0