VYPR
High severity7.3NVD Advisory· Published Jan 19, 2016· Updated Jun 17, 2026

CVE-2016-1904

CVE-2016-1904

Description

Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7.0.2 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a long string to the (1) php_escape_shell_cmd or (2) php_escape_shell_arg function, leading to a heap-based buffer overflow.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • PHP/PHP3 versions
    cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*
    • (no CPE)range: <7.0.2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.