Description
Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger unintended method execution via crafted serialized data.
Remediation
References
Related Vulnerabilities
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9418)
PHP Other Vulnerability (CVE-2005-0525)
MySQL CVE-2021-2032 Vulnerability (CVE-2021-2032)
Chamilo Improper Input Validation Vulnerability (CVE-2021-31933)
WordPress Plugin SEO Redirection-301 Redirect Manager Cross-Site Scripting (7.3)