Description
The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
Remediation
References
Related Vulnerabilities
WordPress Plugin Premium SEO Pack Multiple Vulnerabilities (1.8.0)
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949)
WebLogic Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1324)
MongoDb Heap-based Buffer Overflow Vulnerability (CVE-2025-0755)