← Back to CVE List

CVE-2016-7480

Published: 2017-01-11T07:59Z
Last Modified: 2024-11-21T02:58Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt