Php-pecl-http
Vulnerabilities
2
Known exploited
0
Max CVSS
9.8
Top EPSS
0.06797
Severity breakdown
Critical
2
High
0
Medium
0
Low
0
Also matched as (raw): php-pecl-http
Top vulnerabilities
CVE-2016-7398A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.
CVE-2016-5873Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable characters in a URL.