Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2016-9936 The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) o… PHP Patch available Fix from $2,3002017-01-04 HIGH 7.5 CVE-2016-9934EPSS 7% ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafte… PHP after 5.6.27 Fix from $1,9502017-01-04 CRITICAL 9.8 CVE-2016-7568EPSS 5% Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, all… PHP after 7.0.11 Fix from $2,3002016-09-28 HIGH 7.5 CVE-2016-7418EPSS 11% The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service… PHP after 5.6.25 Fix from $1,9502016-09-17 CRITICAL 9.8 CVE-2016-7417EPSS 7% ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type… PHP after 5.6.25 Fix from $2,3002016-09-17 HIGH 7.5 CVE-2016-7416EPSS 7% ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale … PHP after 5.6.25 Fix from $1,9502016-09-17 CRITICAL 9.8 CVE-2016-7414EPSS 7% The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enoug… PHP after 5.6.25 Fix from $2,3002016-09-17 CRITICAL 9.8 CVE-2016-7413EPSS 7% Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers… PHP after 5.6.25 Fix from $2,3002016-09-17 HIGH 8.1 CVE-2016-7412EPSS 9% ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allo… PHP after 5.6.25 Fix from $1,9502016-09-17 CRITICAL 9.8 CVE-2016-7134 ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of ser… PHP Patch available Fix from $2,3002016-09-12 HIGH 8.1 CVE-2016-7133 Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause … PHP Patch available Fix from $1,9502016-09-12 HIGH 7.5 CVE-2016-7132EPSS 9% ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and applica… PHP after 5.6.24 Fix from $1,9502016-09-12 HIGH 7.5 CVE-2016-7131EPSS 9% ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and applica… PHP after 5.6.24 Fix from $1,9502016-09-12 HIGH 7.5 CVE-2016-7130EPSS 7% The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service … PHP after 5.6.24 Fix from $1,9502016-09-12 CRITICAL 9.8 CVE-2016-7129EPSS 7% The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service… PHP after 5.6.24 Fix from $2,3002016-09-12 MEDIUM 5.3 CVE-2016-7128EPSS 8% The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that ex… PHP after 5.6.24 Fix from $1,6002016-09-12 CRITICAL 9.8 CVE-2016-7127EPSS 7% The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamma values, which allows remote… PHP after 5.6.24 Fix from $2,3002016-09-12 CRITICAL 9.8 CVE-2016-7126EPSS 9% The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which… PHP after 5.6.24 Fix from $2,3002016-09-12 HIGH 7.5 CVE-2016-7125EPSS 6% ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows r… PHP after 5.6.24 Fix from $1,9502016-09-12 CRITICAL 9.8 CVE-2016-7124EPSS 17% ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause… PHP after 5.6.24 Fix from $2,3002016-09-12 CRITICAL 9.8 CVE-2016-5772EPSS 10% Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x be… PHP 5.5.37 / 5.6.23+ Fix from $2,3002016-08-07 CRITICAL 9.8 CVE-2016-5771EPSS 15% spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage co… PHP 5.5.37 / 5.6.23+ Fix from $2,3002016-08-07 CRITICAL 9.8 CVE-2016-5770EPSS 7% Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows rem… PHP 5.5.37 / 5.6.23+ Fix from $2,3002016-08-07 CRITICAL 9.8 CVE-2016-3132EPSS 12% Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to e… PHP Patch available Fix from $2,3002016-08-07 CRITICAL 9.8 CVE-2016-3078EPSS 56% Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buff… PHP 7.0.6+ Fix from $2,3002016-08-07 HIGH 8.1 CVE-2016-6174EPSS 12% applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) bef… PHP after 5.4.23 Fix from $1,9502016-07-12 CRITICAL 9.8 CVE-2016-4544EPSS 7% The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF star… PHP 5.5.35 / 5.6.21+ Fix from $2,3002016-05-22 CRITICAL 9.8 CVE-2016-4543EPSS 12% The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes,… PHP after 7.5.5.6 Fix from $2,3002016-05-22 CRITICAL 9.8 CVE-2016-4346EPSS 6% Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibl… PHP 7.0.4+ Fix from $2,3002016-05-22 CRITICAL 9.8 CVE-2016-4345EPSS 5% Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a deni… PHP 7.0.4+ Fix from $2,3002016-05-22