Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 883

Количество 3 883

redhat логотип

CVE-2016-6292

больше 9 лет назад

The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted JPEG image.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2016-6292

больше 9 лет назад

The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted JPEG image.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2016-6292

больше 9 лет назад

The exif_process_user_comment function in ext/exif/exif.c in PHP befor ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-6291

больше 9 лет назад

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2016-6291

больше 9 лет назад

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2016-6291

больше 9 лет назад

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-6291

больше 9 лет назад

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP b ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-6290

больше 9 лет назад

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2016-6290

больше 9 лет назад

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2016-6290

больше 9 лет назад

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-6290

больше 9 лет назад

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7 ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-6289

больше 9 лет назад

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2016-6289

больше 9 лет назад

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-6289

больше 9 лет назад

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2016-6289

больше 9 лет назад

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_ ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-6288

больше 9 лет назад

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2016-6288

больше 10 лет назад

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2016-6288

больше 9 лет назад

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-6288

больше 9 лет назад

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5. ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-5773

больше 9 лет назад

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2016-6292

The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted JPEG image.

CVSS3: 6.2
6%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6292

The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted JPEG image.

CVSS3: 6.5
6%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6292

The exif_process_user_comment function in ext/exif/exif.c in PHP befor ...

CVSS3: 6.5
6%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-6291

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.

CVSS3: 9.8
7%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-6291

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.

CVSS3: 4.8
7%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6291

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.

CVSS3: 9.8
7%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6291

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP b ...

CVSS3: 9.8
7%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-6290

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.

CVSS3: 9.8
8%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-6290

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.

CVSS3: 7
8%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6290

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.

CVSS3: 9.8
8%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6290

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7 ...

CVSS3: 9.8
8%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-6289

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.

CVSS3: 7.8
2%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-6289

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.

CVSS3: 5.3
2%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6289

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.

CVSS3: 7.8
2%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6289

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_ ...

CVSS3: 7.8
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-6288

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 9.8
4%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-6288

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 6.2
4%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-6288

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 9.8
4%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6288

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5. ...

CVSS3: 9.8
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-5773

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

CVSS3: 9.8
22%
Средний
больше 9 лет назад

Уязвимостей на страницу