CVE-2016-1904: PHP
High severity, CVSS 7.3. EPSS: 2.7% chance of exploitation in the next 30 days.
Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7.0.2 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a long string to the (1) php_escape_shell_cmd or (2) php_escape_shell_arg function, leading to a heap-based buffer overflow.
Affected products
- PHP PHP: version 7.0.0 only; version 7.0.1 only
Published 2016-01-19. Last modified 2026-06-17.