5
CVSSv2

CVE-2016-9934

Published: 04/01/2017 Updated: 04/05/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

ext/wddx/wddx.c in PHP prior to 5.6.28 and 7.x prior to 7.0.13 allows remote malicious users to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php 7.0.4

php php 7.0.5

php php

php php 7.0.0

php php 7.0.1

php php 7.0.8

php php 7.0.9

php php 7.0.6

php php 7.0.7

php php 7.0.2

php php 7.0.3

php php 7.0.10

php php 7.0.11

php php 7.0.12

Vendor Advisories

Synopsis Moderate: rh-php70-php security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-php70-php is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Several security issues were fixed in PHP ...
The SplObjectStorage unserialize implementation in ext/spl/spl_observerc in PHP before 7012 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data (CVE-2016-7480) Use-after-free vulnerability in the CURLFile implement ...
A vulnerability was found in gd Integer underflow in a calculation in dynamicGetbuf() was incorrectly handled, leading in some circumstances to an out of bounds write through a very large argument to memcpy() An attacker could create a crafted image that would lead to a crash or, potentially, code execution (CVE-2016-8670) Use-after-free vulnera ...
It has been discovered that ext/wddx/wddxc in PHP before 5628 and 7x before 7013 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string ...