CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
56606 | CVE-2012-3363 | Candidate | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack. | Assigned (20120614) | None (candidate not yet proposed) | View | |
19121 | CVE-2006-3017 | Candidate | zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x before 5.1.3 can cause zend_hash_del to delete the wrong element, which prevents a variable from being unset even when the PHP unset function is called, which might cause the variable"s value to be used in security-relevant operations. | Assigned (20060614) | None (candidate not yet proposed) | View | |
102160 | CVE-2017-5340 | Candidate | Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data. | Assigned (20170111) | None (candidate not yet proposed) | View | |
94298 | CVE-2016-7478 | Candidate | Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876. | Assigned (20160909) | None (candidate not yet proposed) | View | |
86153 | CVE-2015-8876 | Candidate | Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger unintended method execution via crafted serialized data. | Assigned (20160521) | None (candidate not yet proposed) | View |
Page 30 of 20943, showing 5 records out of 104715 total, starting on record 146, ending on 150