Search CVE reports


Toggle filters

191 – 200 of 687 results

Status is adjusted based on your filters.


CVE-2016-10161

Low priority

The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via...

2 affected packages

php5, php7.0

Package 24.04 LTS
php5 —
php7.0 —
Show less packages

CVE-2016-10160

Medium priority

Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a...

2 affected packages

php5, php7.0

Package 24.04 LTS
php5 —
php7.0 —
Show less packages

CVE-2016-10159

Low priority

Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or application crash) via a truncated...

2 affected packages

php5, php7.0

Package 24.04 LTS
php5 —
php7.0 —
Show less packages

CVE-2016-10158

Low priority

The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers...

2 affected packages

php5, php7.0

Package 24.04 LTS
php5 —
php7.0 —
Show less packages

CVE-2016-7480

Medium priority

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of...

2 affected packages

php5, php7.0

Package 24.04 LTS
php5 —
php7.0 —
Show less packages

CVE-2016-7479

Medium priority

In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution.

2 affected packages

php5, php7.0

Package 24.04 LTS
php5 —
php7.0 —
Show less packages

CVE-2016-7478

Medium priority

Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876.

2 affected packages

php5, php7.0

Package 24.04 LTS
php5 —
php7.0 —
Show less packages

CVE-2016-9138

Low priority

Not in release

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted...

6 affected packages

php5, php7.0, php7.2, php7.4, php8.0, php8.1

Package 24.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Not in release
php7.4 Not in release
php8.0 Not in release
php8.1 Not in release
Show less packages

CVE-2016-9935

Medium priority

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other...

2 affected packages

php5, php7.0

Package 24.04 LTS
php5 —
php7.0 —
Show less packages

CVE-2016-9934

Medium priority

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.

2 affected packages

php5, php7.0

Package 24.04 LTS
php5 —
php7.0 —
Show less packages