Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2016-9936
The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) o…
PHP
Patch available
HIGH 7.5
CVE-2016-9934EPSS 7%
ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafte…
PHP
after 5.6.27
CRITICAL 9.8
CVE-2016-7568EPSS 5%
Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, all…
PHP
after 7.0.11
HIGH 7.5
CVE-2016-7418EPSS 11%
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service…
PHP
after 5.6.25
CRITICAL 9.8
CVE-2016-7417EPSS 7%
ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type…
PHP
after 5.6.25
HIGH 7.5
CVE-2016-7416EPSS 7%
ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale …
PHP
after 5.6.25
CRITICAL 9.8
CVE-2016-7414EPSS 7%
The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enoug…
PHP
after 5.6.25
CRITICAL 9.8
CVE-2016-7413EPSS 7%
Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers…
PHP
after 5.6.25
HIGH 8.1
CVE-2016-7412EPSS 9%
ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allo…
PHP
after 5.6.25
CRITICAL 9.8
CVE-2016-7134
ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of ser…
PHP
Patch available
HIGH 8.1
CVE-2016-7133
Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause …
PHP
Patch available
HIGH 7.5
CVE-2016-7132EPSS 9%
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and applica…
PHP
after 5.6.24
HIGH 7.5
CVE-2016-7131EPSS 9%
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and applica…
PHP
after 5.6.24
HIGH 7.5
CVE-2016-7130EPSS 7%
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service …
PHP
after 5.6.24
CRITICAL 9.8
CVE-2016-7129EPSS 7%
The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service…
PHP
after 5.6.24
MEDIUM 5.3
CVE-2016-7128EPSS 8%
The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that ex…
PHP
after 5.6.24
CRITICAL 9.8
CVE-2016-7127EPSS 7%
The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamma values, which allows remote…
PHP
after 5.6.24
CRITICAL 9.8
CVE-2016-7126EPSS 9%
The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which…
PHP
after 5.6.24
HIGH 7.5
CVE-2016-7125EPSS 6%
ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows r…
PHP
after 5.6.24
CRITICAL 9.8
CVE-2016-7124EPSS 17%
ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause…
PHP
after 5.6.24
CRITICAL 9.8
CVE-2016-5772EPSS 10%
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x be…
PHP
5.5.37 / 5.6.23+
CRITICAL 9.8
CVE-2016-5771EPSS 15%
spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage co…
PHP
5.5.37 / 5.6.23+
CRITICAL 9.8
CVE-2016-5770EPSS 7%
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows rem…
PHP
5.5.37 / 5.6.23+
CRITICAL 9.8
CVE-2016-3132EPSS 12%
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to e…
PHP
Patch available
CRITICAL 9.8
CVE-2016-3078EPSS 56%
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buff…
PHP
7.0.6+
HIGH 8.1
CVE-2016-6174EPSS 12%
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) bef…
PHP
after 5.4.23
CRITICAL 9.8
CVE-2016-4544EPSS 7%
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF star…
PHP
5.5.35 / 5.6.21+
CRITICAL 9.8
CVE-2016-4543EPSS 12%
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes,…
PHP
after 7.5.5.6
CRITICAL 9.8
CVE-2016-4346EPSS 6%
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibl…
PHP
7.0.4+
CRITICAL 9.8
CVE-2016-4345EPSS 5%
Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a deni…
PHP
7.0.4+