CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93951  CVE-2016-7131  Candidate  ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via a malformed wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a tag that lacks a < (less than) character.  Assigned (20160902)  None (candidate not yet proposed)    View
93952  CVE-2016-7132  Candidate  ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a stray element inside a boolean element, leading to incorrect pop processing.  Assigned (20160902)  None (candidate not yet proposed)    View
93953  CVE-2016-7133  Candidate  Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.  Assigned (20160902)  None (candidate not yet proposed)    View
93954  CVE-2016-7134  Candidate  ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.  Assigned (20160902)  None (candidate not yet proposed)    View
93955  CVE-2016-7135  Candidate  Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.  Assigned (20160905)  None (candidate not yet proposed)    View

Page 18791 of 20943, showing 5 records out of 104715 total, starting on record 93951, ending on 93955

Actions