Description
The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6834.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (5.7)
MySQL CVE-2017-10155 Vulnerability (CVE-2017-10155)
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2019-4156)
WordPress Plugin Swift Landing Page Cross-Site Request Forgery (1.1)
WordPress Plugin Vodpod Video Gallery 'gid' Parameter Cross-Site Scripting (3.1.5)