Show filters
53 Total Results
Displaying 1-10 of 53
Sort by:
Attacker Value
Unknown
CVE-2016-4473
Disclosure Date: June 08, 2017 (last updated November 26, 2024)
/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833.
0
Attacker Value
Unknown
CVE-2016-5093
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
The get_icu_value_internal function in ext/intl/locale/locale_methods.c in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7 does not ensure the presence of a '\0' character, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted locale_get_primary_language call.
0
Attacker Value
Unknown
CVE-2016-5769
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted length value, related to the (1) mcrypt_generic and (2) mdecrypt_generic functions.
0
Attacker Value
Unknown
CVE-2016-5095
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Integer overflow in the php_escape_html_entities_ex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from a FILTER_SANITIZE_FULL_SPECIAL_CHARS filter_var call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-5094.
0
Attacker Value
Unknown
CVE-2016-5773
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.
0
Attacker Value
Unknown
CVE-2016-5768
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by leveraging a callback exception.
0
Attacker Value
Unknown
CVE-2016-5096
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Integer overflow in the fread function in ext/standard/file.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer in the second argument.
0
Attacker Value
Unknown
CVE-2016-5114
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and buffer overflow) via a long string, as demonstrated by a long URI in a configuration with custom REQUEST_URI logging.
0
Attacker Value
Unknown
CVE-2016-5094
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Integer overflow in the php_html_entities function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from the htmlspecialchars function.
0
Attacker Value
Unknown
CVE-2016-6296
Disclosure Date: July 25, 2016 (last updated November 08, 2023)
Integer signedness error in the simplestring_addn function in simplestring.c in xmlrpc-epi through 0.54.2, as used in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a long first argument to the PHP xmlrpc_encode_request function.
0