Vulnerability record · CVE-2016-10162 · published 24 January 2017
CVE-2016-10162: Php null pointer dereference vulnerability
Php · Php
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.
Description
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://php.net/ChangeLog-7.php | Release NotesVendor Advisory |
| http://www.securityfocus.com/bid/95668 | |
| http://www.securitytracker.com/id/1037659 | |
| https://access.redhat.com/errata/RHSA-2018:1296 | |
| https://bugs.php.net/bug.php?id=73831 | Issue Tracking |
| https://github.com/php/php-src/commit/8d2539fa0faf3f63e1d1e7635347c5b9e777d47b | Issue TrackingPatchThird Party Advisory |
| http://php.net/ChangeLog-7.php | Release NotesVendor Advisory |
| http://www.securityfocus.com/bid/95668 | |
| http://www.securitytracker.com/id/1037659 | |
| https://access.redhat.com/errata/RHSA-2018:1296 | |
| https://bugs.php.net/bug.php?id=73831 | Issue Tracking |
| https://github.com/php/php-src/commit/8d2539fa0faf3f63e1d1e7635347c5b9e777d47b | Issue TrackingPatchThird Party Advisory |
Track CVE-2016-10162 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-10162), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.