6.4
CVSSv2

CVE-2016-3185

Published: 16/05/2016 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

The make_http_soap_request function in ext/soap/php_http.c in PHP prior to 5.4.44, 5.5.x prior to 5.5.28, 5.6.x prior to 5.6.12, and 7.x prior to 7.0.4 allows remote malicious users to obtain sensitive information from process memory or cause a denial of service (type confusion and application crash) via crafted serialized _cookies data, related to the SoapClient::__call method in ext/soap/soap.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.6.1

php php 5.6.0

php php 5.6.5

php php 5.6.4

php php 5.6.6

php php 5.6.11

php php 5.6.2

php php 5.6.10

php php 5.6.7

php php 5.6.9

php php 5.6.3

php php 5.6.8

php php

php php 7.0.3

php php 7.0.1

php php 7.0.2

php php 7.0.0

php php 5.5.0

php php 5.5.19

php php 5.5.25

php php 5.5.16

php php 5.5.1

php php 5.5.5

php php 5.5.21

php php 5.5.17

php php 5.5.14

php php 5.5.7

php php 5.5.12

php php 5.5.6

php php 5.5.3

php php 5.5.23

php php 5.5.8

php php 5.5.27

php php 5.5.24

php php 5.5.15

php php 5.5.11

php php 5.5.13

php php 5.5.4

php php 5.5.26

php php 5.5.10

php php 5.5.22

php php 5.5.18

php php 5.5.20

php php 5.5.2

php php 5.5.9

Vendor Advisories

USN-2952-1 caused a regression in PHP ...
Several security issues were fixed in PHP ...
The make_http_soap_request function in ext/soap/php_httpc in PHP before 5444, 55x before 5528, 56x before 5612, and 7x before 704 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (type confusion and application crash) via crafted serialized _cookies data, related to the SoapClien ...