Lucene search

K
prionPRIOn knowledge basePRION:CVE-2016-7411
HistorySep 17, 2016 - 9:59 p.m.

Deserialization of untrusted data

2016-09-1721:59:00
PRIOn knowledge base
www.prio-n.com
8

7.8 High

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.4%

ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an unserialize call that references a partially constructed object.

CPENameOperatorVersion
phple5.6.25