CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93111  CVE-2016-6291  Candidate  The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.  Assigned (20160724)  None (candidate not yet proposed)    View
93112  CVE-2016-6292  Candidate  The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted JPEG image.  Assigned (20160724)  None (candidate not yet proposed)    View
93113  CVE-2016-6293  Candidate  The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a "" character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.  Assigned (20160724)  None (candidate not yet proposed)    View
93114  CVE-2016-6294  Candidate  The locale_accept_from_http function in ext/intl/locale/locale_methods.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly restrict calls to the ICU uloc_acceptLanguageFromHTTP function, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long argument.  Assigned (20160724)  None (candidate not yet proposed)    View
93115  CVE-2016-6295  Candidate  ext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via crafted serialized data, a related issue to CVE-2016-5773.  Assigned (20160724)  None (candidate not yet proposed)    View

Page 18623 of 20943, showing 5 records out of 104715 total, starting on record 93111, ending on 93115

Actions