|
265091
|
7.5 |
HIGH
Network
|
php
|
php
|
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) o…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-7130
|
2024-11-21 11:57 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265092
|
9.8 |
CRITICAL
Network
|
php
|
php
|
The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified…
|
CWE-20
Improper Input Validation
|
CVE-2016-7129
|
2024-11-21 11:57 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265093
|
5.3 |
MEDIUM
Network
|
php
|
php
|
The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that exceeds the file size, which allows remote attackers…
|
CWE-200
Information Exposure
|
CVE-2016-7128
|
2024-11-21 11:57 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265094
|
9.8 |
CRITICAL
Network
|
php
|
php
|
The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamma values, which allows remote attackers to cause a denial of service (out-of-bo…
|
CWE-787
Out-of-bounds Write
|
CVE-2016-7127
|
2024-11-21 11:57 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265095
|
9.8 |
CRITICAL
Network
|
php
|
php
|
The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which allows remote attackers to cause a denial of serv…
|
CWE-787
Out-of-bounds Write
|
CVE-2016-7126
|
2024-11-21 11:57 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265096
|
7.5 |
HIGH
Network
|
php
|
php
|
ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session d…
|
CWE-74
Injection
|
CVE-2016-7125
|
2024-11-21 11:57 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265097
|
9.8 |
CRITICAL
Network
|
php
|
php
|
ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-7124
|
2024-11-21 11:57 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265098
|
8.8 |
HIGH
Network
|
google
|
chrome
|
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows …
|
CWE-19
Data Processing Errors
|
CVE-2016-7395
|
2024-11-21 11:57 |
2016-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265099
|
5.9 |
MEDIUM
Network
|
debian wireshark
|
debian_linux wireshark
|
epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant, which allows remote attackers to cause a denial …
|
CWE-416
Use After Free
|
CVE-2016-7180
|
2024-11-21 11:57 |
2016-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265100
|
5.9 |
MEDIUM
Network
|
debian wireshark
|
debian_linux wireshark
|
Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remote attackers to cause a denial of service (applicat…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7179
|
2024-11-21 11:57 |
2016-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|