9.8
CVSSv3

CVE-2016-3141

Published: 31/03/2016 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP prior to 5.5.33 and 5.6.x prior to 5.6.19 allows remote malicious users to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

php php 5.6.1

php php 5.6.5

php php 5.6.12

php php 5.6.13

php php 5.6.0

php php 5.6.4

php php 5.6.6

php php 5.6.18

php php 5.6.11

php php 5.6.2

php php 5.6.10

php php 5.6.7

php php 5.6.15

php php

php php 5.6.17

php php 5.6.16

php php 5.6.9

php php 5.6.3

php php 5.6.8

php php 5.6.14

Vendor Advisories

Synopsis Moderate: rh-php56 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-php56, rh-php56-php, and rh-php56-php-pear is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Mo ...
USN-2952-1 caused a regression in PHP ...
Several security issues were fixed in PHP ...
Use-after-free vulnerability in wddxc in the WDDX extension in PHP before 5533 and 56x before 5619 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element ...

Github Repositories

CVE-2016-3141

CVE-2016-3141 1 Vulnerability Detail Use-after-free vulnerability in wddxc in the WDDX extension in PHP before 5533 and 56x before 5619 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element 2 Overview Bu