← All CVEs

CVE-2016-7478

high · 7.5

Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876.

7.5
CVSS
42.4%
EPSS (exploit prob.)
99th
EPSS percentile
2017-01-11
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

VendorProductAffected versions
phpphp5.0.0
phpphp5.0.0
phpphp5.0.0
phpphp5.0.0
phpphp5.0.0
phpphp5.0.0
phpphp5.0.0
phpphp5.0.0
phpphp5.0.1
phpphp5.0.2
phpphp5.0.3
phpphp5.0.4
phpphp5.0.5
phpphp5.1.0
phpphp5.1.1
phpphp5.1.2
phpphp5.1.3
phpphp5.1.4
phpphp5.1.5
phpphp5.1.6
phpphp5.2.0
phpphp5.2.1
phpphp5.2.2
phpphp5.2.3
phpphp5.2.4
phpphp5.2.5
phpphp5.2.6
phpphp5.2.7
phpphp5.2.8
phpphp5.2.9
phpphp5.2.10
phpphp5.2.11
phpphp5.2.12
phpphp5.2.13
phpphp5.2.14
phpphp5.2.15
phpphp5.2.16
phpphp5.2.17
phpphp5.3.0
phpphp5.3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-7478