CVE Database
/

CVE-2016-7480

Back to search

CVE-2016-7480

Published: Jan 11, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

VendorProductVersions

n/a

PHP before 7.0.12

affected
PHP before 7.0.12

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now