CVE-2016-8876
published 2016-10-31CVE-2016-8876: Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute…
PriorityP342high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EPSS
2.19%
80.5th percentile
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at FoxitReader."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxitsoftware | phantompdf | <= 8.0.5 | — |
| foxitsoftware | reader | <= 8.0.5 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p4hj-x8wm-pqjj: Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8
ghsa_unreviewed·2022-05-17
CVE-2016-8876 [HIGH] CWE-125 GHSA-p4hj-x8wm-pqjj: Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at FoxitReader."
Red Hat
php: Unserialize Exception object can lead to infinite loop
vendor_redhat·2016-09-15·CVSS 9.8
CVE-2016-7478 [CRITICAL] php: Unserialize Exception object can lead to infinite loop
php: Unserialize Exception object can lead to infinite loop
Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876.
Package: php (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Will not fix
Package: php (Red Hat OpenShift Enterprise 2) - Will not fix
Package: rh-php56-php (Red Hat Software Collections) - Will not fix
Package: rh-php70-php (Red Hat Software Collections) - Will not fix
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-10-31
Published