Show filters
117 Total Results
Displaying 91-100 of 117
Sort by:
Attacker Value
Unknown

CVE-2016-4544

Disclosure Date: May 22, 2016 (last updated November 08, 2023)
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
Attacker Value
Unknown

CVE-2016-4540

Disclosure Date: May 22, 2016 (last updated November 08, 2023)
The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a negative offset.
0
Attacker Value
Unknown

CVE-2016-4541

Disclosure Date: May 22, 2016 (last updated November 08, 2023)
The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a negative offset.
0
Attacker Value
Unknown

CVE-2016-4542

Disclosure Date: May 22, 2016 (last updated November 08, 2023)
The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
0
Attacker Value
Unknown

CVE-2016-4538

Disclosure Date: May 22, 2016 (last updated November 08, 2023)
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.
0
Attacker Value
Unknown

CVE-2016-4537

Disclosure Date: May 22, 2016 (last updated November 08, 2023)
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.
0
Attacker Value
Unknown

CVE-2016-4539

Disclosure Date: May 22, 2016 (last updated November 08, 2023)
The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other impact via crafted XML data in the second argument, leading to a parser level of zero.
0
Attacker Value
Unknown

CVE-2016-4543

Disclosure Date: May 22, 2016 (last updated November 08, 2023)
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
0
Attacker Value
Unknown

CVE-2015-7827

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
0
Attacker Value
Unknown

CVE-2016-2850

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
0