Description
Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger unintended method execution via crafted serialized data.
Remediation
References
Related Vulnerabilities
WordPress Plugin Revamp CRM for WooCommerce Local File Inclusion (1.0.3)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2021-37150)
Oracle Database Server CVE-2011-2239 Vulnerability (CVE-2011-2239)
Ruby on Rails URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-44528)
WordPress Plugin Feed Them Social-for Twitter feed, Youtube and more Cross-Site Scripting (1.6.9)