Vulnerabilities > CVE-2018-19396 - Deserialization of Untrusted Data vulnerability in PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
php
CWE-502

Summary

ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.

Vulnerable Configurations

Part Description Count
Application
Php
762

Common Weakness Enumeration (CWE)