[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2016-7126":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":30,"duplicate_of":9,"upstream":31,"downstream":32,"duplicates":47,"related":48,"reserved_at":9,"published_at":54,"modified_at":55,"state":56,"summary":57,"references_raw":65,"kevs":124,"epss":125,"epss_history":128,"metrics":379,"affected":388},"CVE-2016-7126","The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which allows remote attackers to cause a denial of service (select_colors allocation error and out-of-bounds write) or possibly have unspecified other impact via a large value in the third argument.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-787","Out-of-bounds Write","The product writes data past the end, or before the beginning, of the intended buffer.","weakness","Draft","Base","High",[],[21],{"_key":22,"name":23,"source":24,"url":25,"maturity":26,"reliability_score":27,"verified":28,"type":9,"platforms":29,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_E13444A641BD73E4","Exploit Reference (bugs.php.net)","reference","https://bugs.php.net/bug.php?id=72697","unknown",0.2,false,[],[],[],[33,35,37,39,41,43,45],{"_key":34},"SUSE-SU-2016:2328-1",{"_key":36},"SUSE-SU-2016:2408-1",{"_key":38},"SUSE-SU-2016:2459-1",{"_key":40},"SUSE-SU-2016:2460-1",{"_key":42},"SUSE-SU-2016:2460-2",{"_key":44},"DSA-3689-1",{"_key":46},"RHSA-2016:2750",[],[49,50,51,52,53],{"_key":34},{"_key":36},{"_key":38},{"_key":40},{"_key":42},"2016-09-12T01:00:00.000Z","2024-08-06T01:50:47.421Z","Modified",{"cisa_kev":28,"cisa_ransomware":28,"cisa_vendor":9,"epss_severity":58,"epss_score":59,"severity":60,"severity_score":61,"severity_version":62,"severity_source":63,"severity_vector":64,"severity_status":56},"low",0.04632,"critical",9.8,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[66,73,80,86,92,97,102,106,110,116,120],{"url":67,"sources":68,"tags":70},"http://www.php.net/ChangeLog-7.php",[69,63],"cve.org",[71,72],"X Refsource CONFIRM","Release Notes",{"url":74,"sources":75,"tags":76},"https://security.gentoo.org/glsa/201611-22",[69,63],[77,78,79],"Vendor Advisory","X Refsource GENTOO","Third Party Advisory",{"url":81,"sources":82,"tags":83},"http://www.securitytracker.com/id/1036680",[69,63],[84,85,79],"VDB Entry","X Refsource SECTRACK",{"url":87,"sources":88,"tags":89},"https://github.com/php/php-src/commit/b6f13a5ef9d6280cf984826a5de012a32c396cd4?w=1",[69,63],[71,90,91],"Issue Tracking","Patch",{"url":93,"sources":94,"tags":95},"http://rhn.redhat.com/errata/RHSA-2016-2750.html",[69,63],[77,96,79],"X Refsource REDHAT",{"url":98,"sources":99,"tags":100},"http://www.securityfocus.com/bid/92755",[69,63],[84,101,79],"X Refsource BID",{"url":103,"sources":104,"tags":105},"http://www.php.net/ChangeLog-5.php",[69,63],[71,72],{"url":107,"sources":108,"tags":109},"https://www.tenable.com/security/tns-2016-19",[69,63],[71,79],{"url":111,"sources":112,"tags":113},"http://openwall.com/lists/oss-security/2016/09/02/9",[69,63],[114,115],"Mailing List","X Refsource MLIST",{"url":25,"sources":117,"tags":118},[69,63],[71,119,90],"Exploit",{"url":121,"sources":122,"tags":123},"https://github.com/php/php-src/commit/28022c9b1fd937436ab67bb3d61f652c108baf96",[69,63],[71,91,77],[],{"date":126,"score":59,"percentile":127},"2026-06-04",0.89464,[129,132,135,138,140,143,146,149,151,154,157,160,162,164,166,169,172,175,178,180,183,186,189,191,194,197,200,203,206,209,212,215,217,220,222,224,227,230,233,236,238,241,244,246,249,252,255,257,260,263,266,269,272,275,279,282,284,287,290,293,296,299,301,304,307,310,313,316,319,321,324,326,329,331,334,337,340,343,345,348,351,354,357,360,363,366,369,372,374,376],{"date":130,"score":59,"percentile":131},"2025-11-04",0.88775,{"date":133,"score":59,"percentile":134},"2025-11-05",0.88774,{"date":136,"score":59,"percentile":137},"2025-11-06",0.88767,{"date":139,"score":59,"percentile":134},"2025-11-07",{"date":141,"score":59,"percentile":142},"2025-11-08",0.88776,{"date":144,"score":59,"percentile":145},"2025-11-09",0.88773,{"date":147,"score":59,"percentile":148},"2025-11-10",0.8877,{"date":150,"score":59,"percentile":134},"2025-11-11",{"date":152,"score":59,"percentile":153},"2025-11-12",0.88781,{"date":155,"score":59,"percentile":156},"2025-11-13",0.88785,{"date":158,"score":59,"percentile":159},"2025-11-14",0.88789,{"date":161,"score":59,"percentile":156},"2025-11-15",{"date":163,"score":59,"percentile":159},"2025-11-16",{"date":165,"score":59,"percentile":156},"2025-11-17",{"date":167,"score":59,"percentile":168},"2025-11-18",0.88203,{"date":170,"score":59,"percentile":171},"2025-11-19",0.88206,{"date":173,"score":59,"percentile":174},"2025-11-20",0.8821,{"date":176,"score":59,"percentile":177},"2025-11-21",0.888,{"date":179,"score":59,"percentile":177},"2025-11-22",{"date":181,"score":59,"percentile":182},"2025-11-23",0.88797,{"date":184,"score":59,"percentile":185},"2025-11-24",0.88798,{"date":187,"score":59,"percentile":188},"2025-11-25",0.88801,{"date":190,"score":59,"percentile":177},"2025-11-26",{"date":192,"score":59,"percentile":193},"2025-11-27",0.88802,{"date":195,"score":59,"percentile":196},"2025-11-28",0.88795,{"date":198,"score":59,"percentile":199},"2025-11-29",0.88866,{"date":201,"score":59,"percentile":202},"2025-11-30",0.88862,{"date":204,"score":59,"percentile":205},"2025-12-01",0.88921,{"date":207,"score":59,"percentile":208},"2025-12-02",0.88923,{"date":210,"score":59,"percentile":211},"2025-12-03",0.8892,{"date":213,"score":59,"percentile":214},"2025-12-04",0.88861,{"date":216,"score":59,"percentile":214},"2025-12-05",{"date":218,"score":59,"percentile":219},"2025-12-06",0.8886,{"date":221,"score":59,"percentile":219},"2025-12-07",{"date":223,"score":59,"percentile":202},"2025-12-08",{"date":225,"score":59,"percentile":226},"2025-12-09",0.8887,{"date":228,"score":59,"percentile":229},"2025-12-10",0.88889,{"date":231,"score":59,"percentile":232},"2025-12-11",0.8889,{"date":234,"score":59,"percentile":235},"2025-12-12",0.88894,{"date":237,"score":59,"percentile":235},"2025-12-13",{"date":239,"score":59,"percentile":240},"2025-12-14",0.88895,{"date":242,"score":59,"percentile":243},"2025-12-15",0.88897,{"date":245,"score":59,"percentile":243},"2025-12-16",{"date":247,"score":59,"percentile":248},"2025-12-17",0.889,{"date":250,"score":59,"percentile":251},"2025-12-18",0.88909,{"date":253,"score":59,"percentile":254},"2025-12-19",0.8891,{"date":256,"score":59,"percentile":251},"2025-12-20",{"date":258,"score":59,"percentile":259},"2025-12-21",0.88918,{"date":261,"score":59,"percentile":262},"2025-12-22",0.88916,{"date":264,"score":59,"percentile":265},"2025-12-23",0.88917,{"date":267,"score":59,"percentile":268},"2025-12-24",0.88925,{"date":270,"score":59,"percentile":271},"2025-12-25",0.88935,{"date":273,"score":59,"percentile":274},"2025-12-26",0.88933,{"date":276,"score":277,"percentile":278},"2025-12-27",0.0209,0.8362,{"date":280,"score":59,"percentile":281},"2025-12-28",0.88929,{"date":283,"score":59,"percentile":268},"2025-12-29",{"date":285,"score":59,"percentile":286},"2025-12-30",0.88931,{"date":288,"score":59,"percentile":289},"2025-12-31",0.8894,{"date":291,"score":59,"percentile":292},"2026-01-01",0.89007,{"date":294,"score":59,"percentile":295},"2026-01-02",0.89001,{"date":297,"score":59,"percentile":298},"2026-01-03",0.88998,{"date":300,"score":59,"percentile":271},"2026-01-04",{"date":302,"score":59,"percentile":303},"2026-01-05",0.88932,{"date":305,"score":59,"percentile":306},"2026-01-06",0.88937,{"date":308,"score":59,"percentile":309},"2026-01-07",0.88939,{"date":311,"score":59,"percentile":312},"2026-01-08",0.88946,{"date":314,"score":59,"percentile":315},"2026-01-09",0.88951,{"date":317,"score":59,"percentile":318},"2026-01-10",0.88953,{"date":320,"score":59,"percentile":312},"2026-01-11",{"date":322,"score":59,"percentile":323},"2026-01-12",0.88943,{"date":325,"score":59,"percentile":309},"2026-01-13",{"date":327,"score":59,"percentile":328},"2026-01-14",0.88952,{"date":330,"score":59,"percentile":315},"2026-01-15",{"date":332,"score":59,"percentile":333},"2026-01-16",0.88958,{"date":335,"score":59,"percentile":336},"2026-01-17",0.88962,{"date":338,"score":59,"percentile":339},"2026-01-18",0.88959,{"date":341,"score":59,"percentile":342},"2026-01-19",0.88956,{"date":344,"score":59,"percentile":333},"2026-01-20",{"date":346,"score":59,"percentile":347},"2026-01-21",0.88963,{"date":349,"score":59,"percentile":350},"2026-01-22",0.88967,{"date":352,"score":59,"percentile":353},"2026-01-23",0.88981,{"date":355,"score":59,"percentile":356},"2026-01-24",0.88988,{"date":358,"score":59,"percentile":359},"2026-01-25",0.88989,{"date":361,"score":59,"percentile":362},"2026-01-26",0.88991,{"date":364,"score":59,"percentile":365},"2026-01-27",0.8899,{"date":367,"score":59,"percentile":368},"2026-01-28",0.88993,{"date":370,"score":59,"percentile":371},"2026-01-29",0.88996,{"date":373,"score":59,"percentile":298},"2026-01-30",{"date":375,"score":59,"percentile":371},"2026-01-31",{"date":377,"score":59,"percentile":378},"2026-02-01",0.89061,[380],{"source":63,"cvss_v2_0":381,"cvss_v3_0":9,"cvss_v3_1":386,"cvss_v4_0":9},{"baseScore":382,"baseSeverity":9,"vectorString":383,"impactScore":384,"exploitabilityScore":385},7.5,"AV:N/AC:L/Au:N/C:P/I:P/A:P",6.4,10,{"baseScore":61,"baseSeverity":387,"vectorString":64,"impactScore":61,"exploitabilityScore":385},"CRITICAL",[389],{"ecosystem":9,"name":390,"vendor":9,"product":390,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":391},"PHP",[392,395,397,399,401,403,405,407,409,411,413],{"version":393,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.0","cpe",{"version":396,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.1",{"version":398,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.2",{"version":400,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.3",{"version":402,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.4",{"version":404,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.5",{"version":406,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.6",{"version":408,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.7",{"version":410,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.8",{"version":412,"is_range":28,"range_type":394,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.9",{"version":414,"is_range":415,"range_type":394,"version_start":9,"version_start_type":9,"version_end":416,"version_end_type":417,"fixed_in":9},"lte5.6.24",true,"5.6.24","including"]