|
265401
|
9.8 |
CRITICAL
Network
|
php opensuse fedoraproject debian
|
php leap opensuse fedora debian_linux
|
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a d…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4544
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265402
|
9.8 |
CRITICAL
Network
|
hp php fedoraproject opensuse
|
system_management_homepage php fedora leap
|
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4543
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265403
|
9.8 |
CRITICAL
Network
|
php opensuse fedoraproject
|
php leap fedora
|
The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4542
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265404
|
9.8 |
CRITICAL
Network
|
fedoraproject php opensuse
|
fedora php leap
|
The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds…
|
NVD-CWE-Other
|
CVE-2016-4541
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265405
|
9.8 |
CRITICAL
Network
|
fedoraproject opensuse php
|
fedora leap php
|
The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bound…
|
NVD-CWE-Other
|
CVE-2016-4540
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265406
|
9.8 |
CRITICAL
Network
|
php opensuse fedoraproject
|
php leap fedora
|
The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segment…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4539
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265407
|
9.8 |
CRITICAL
Network
|
php fedoraproject opensuse
|
php fedora leap
|
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_…
|
CWE-20
Improper Input Validation
|
CVE-2016-4538
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265408
|
9.8 |
CRITICAL
Network
|
php opensuse fedoraproject
|
php leap fedora
|
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause …
|
CWE-20
Improper Input Validation
|
CVE-2016-4537
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265409
|
6.0 |
MEDIUM
Local
|
qemu canonical debian
|
qemu ubuntu_linux debian_linux
|
The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of servi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4441
|
2024-11-21 11:52 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265410
|
6.7 |
MEDIUM
Local
|
canonical qemu debian
|
ubuntu_linux qemu debian_linux
|
The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4439
|
2024-11-21 11:52 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|