Description
Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger unintended method execution via crafted serialized data.
Remediation
References
Related Vulnerabilities
WordPress Plugin WooCommerce Information Disclosure (4.5.2)
WordPress Plugin Quotes and Tips by BestWebSoft Cross-Site Scripting (1.19)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5288)
Oracle Database Server CVE-2006-0291 Vulnerability (CVE-2006-0291)
WordPress Plugin Wordpress Membership SwiftCloud.io SQL Injection (1.0)