CVE-2016-9865
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
- Affected products
- Alt Linux, Phpmyadmin
- Phpmyadmin
- = 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4.1, 4.0.4.2, 4.0.5, 4.0.6, 4.0.7, 4.0.8, 4.0.9, 4.0.10, 4.0.10.1, 4.0.10.2, 4.0.10.3, 4.0.10.4, 4.0.10.5, 4.0.10.6, 4.0.10.7, 4.0.10.8, 4.0.10.9, 4.0.10.10, 4.0.10.11, 4.0.10.12, 4.0.10.13, 4.0.10.14, 4.0.10.15, 4.0.10.16, 4.0.10.17
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 2.3% (81th percentile)
- Weakness
- CWE-254, CWE-502
- NVD status
- Modified
- Published
- 2016-12-11
CVE-2016-9865 at NVD
No indexed exploits for CVE-2016-9865 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2016-9865 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.