Search CVE reports


Toggle filters

161 – 170 of 259 results


CVE-2016-7479

Medium priority
Fixed

In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution.

2 affected packages

php5, php7.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
php7.0
Show less packages

CVE-2016-7478

Medium priority
Fixed

Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876.

2 affected packages

php5, php7.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
php7.0
Show less packages

CVE-2016-9138

Low priority
Vulnerable

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted...

6 affected packages

php7.4, php7.0, php7.2, php5, php8.1, php8.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.4 Not in release Not in release Vulnerable Not in release
php7.0 Not in release Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Vulnerable
php5 Not in release Not in release Not in release Not in release
php8.1 Not in release Vulnerable Not in release Not in release
php8.0 Not in release Not in release Not in release Not in release
Show less packages

CVE-2016-9936

Medium priority
Fixed

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this...

1 affected package

php7.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.0
Show less packages

CVE-2016-9935

Medium priority
Fixed

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other...

2 affected packages

php7.0, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.0
php5
Show less packages

CVE-2016-9934

Medium priority
Fixed

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.

2 affected packages

php5, php7.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
php7.0
Show less packages

CVE-2016-9933

Low priority
Fixed

Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial...

3 affected packages

libgd2, php5, php7.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgd2
php5
php7.0
Show less packages

CVE-2016-9137

Low priority
Fixed

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via...

2 affected packages

php7.0, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.0
php5
Show less packages

CVE-2014-9912

Low priority
Fixed

The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote...

2 affected packages

php7.0, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.0
php5
Show less packages

CVE-2016-6906

Low priority
Fixed

The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.

3 affected packages

php7.0, libgd2, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.0
libgd2
php5
Show less packages