Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PHP CRITICAL 9.8
CVE-2016-9936

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) o…

Patch available
Fix from $2,300 2017-01-04
PHP HIGH 7.5
CVE-2016-9934EPSS 7%

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafte…

Fix: after 5.6.27
Fix from $1,950 2017-01-04
PHP CRITICAL 9.8
CVE-2016-7568EPSS 5%

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, all…

Fix: after 7.0.11
Fix from $2,300 2016-09-28
PHP HIGH 7.5
CVE-2016-7418EPSS 11%

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service…

Fix: after 5.6.25
Fix from $1,950 2016-09-17
PHP CRITICAL 9.8
CVE-2016-7417EPSS 7%

ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type…

Fix: after 5.6.25
Fix from $2,300 2016-09-17
PHP HIGH 7.5
CVE-2016-7416EPSS 7%

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale …

Fix: after 5.6.25
Fix from $1,950 2016-09-17
PHP CRITICAL 9.8
CVE-2016-7414EPSS 7%

The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enoug…

Fix: after 5.6.25
Fix from $2,300 2016-09-17
PHP CRITICAL 9.8
CVE-2016-7413EPSS 7%

Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers…

Fix: after 5.6.25
Fix from $2,300 2016-09-17
PHP HIGH 8.1
CVE-2016-7412EPSS 9%

ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allo…

Fix: after 5.6.25
Fix from $1,950 2016-09-17
PHP CRITICAL 9.8
CVE-2016-7134

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of ser…

Patch available
Fix from $2,300 2016-09-12
PHP HIGH 8.1
CVE-2016-7133

Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause …

Patch available
Fix from $1,950 2016-09-12
PHP HIGH 7.5
CVE-2016-7132EPSS 9%

ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and applica…

Fix: after 5.6.24
Fix from $1,950 2016-09-12
PHP HIGH 7.5
CVE-2016-7131EPSS 9%

ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and applica…

Fix: after 5.6.24
Fix from $1,950 2016-09-12
PHP HIGH 7.5
CVE-2016-7130EPSS 7%

The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service …

Fix: after 5.6.24
Fix from $1,950 2016-09-12
PHP CRITICAL 9.8
CVE-2016-7129EPSS 7%

The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service…

Fix: after 5.6.24
Fix from $2,300 2016-09-12
PHP MEDIUM 5.3
CVE-2016-7128EPSS 8%

The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that ex…

Fix: after 5.6.24
Fix from $1,600 2016-09-12
PHP CRITICAL 9.8
CVE-2016-7127EPSS 7%

The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamma values, which allows remote…

Fix: after 5.6.24
Fix from $2,300 2016-09-12
PHP CRITICAL 9.8
CVE-2016-7126EPSS 9%

The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which…

Fix: after 5.6.24
Fix from $2,300 2016-09-12
PHP HIGH 7.5
CVE-2016-7125EPSS 6%

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows r…

Fix: after 5.6.24
Fix from $1,950 2016-09-12
PHP CRITICAL 9.8
CVE-2016-7124EPSS 17%

ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause…

Fix: after 5.6.24
Fix from $2,300 2016-09-12
PHP CRITICAL 9.8
CVE-2016-5772EPSS 10%

Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x be…

Fix: 5.5.37 / 5.6.23+
Fix from $2,300 2016-08-07
PHP CRITICAL 9.8
CVE-2016-5771EPSS 15%

spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage co…

Fix: 5.5.37 / 5.6.23+
Fix from $2,300 2016-08-07
PHP CRITICAL 9.8
CVE-2016-5770EPSS 7%

Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows rem…

Fix: 5.5.37 / 5.6.23+
Fix from $2,300 2016-08-07
PHP CRITICAL 9.8
CVE-2016-3132EPSS 12%

Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to e…

Patch available
Fix from $2,300 2016-08-07
PHP CRITICAL 9.8
CVE-2016-3078EPSS 56%

Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buff…

Fix: 7.0.6+
Fix from $2,300 2016-08-07
PHP HIGH 8.1
CVE-2016-6174EPSS 12%

applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) bef…

Fix: after 5.4.23
Fix from $1,950 2016-07-12
PHP CRITICAL 9.8
CVE-2016-4544EPSS 7%

The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF star…

Fix: 5.5.35 / 5.6.21+
Fix from $2,300 2016-05-22
PHP CRITICAL 9.8
CVE-2016-4543EPSS 12%

The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes,…

Fix: after 7.5.5.6
Fix from $2,300 2016-05-22
PHP CRITICAL 9.8
CVE-2016-4346EPSS 6%

Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibl…

Fix: 7.0.4+
Fix from $2,300 2016-05-22
PHP CRITICAL 9.8
CVE-2016-4345EPSS 5%

Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a deni…

Fix: 7.0.4+
Fix from $2,300 2016-05-22