[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2016-9137":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":30,"duplicate_of":9,"upstream":31,"downstream":32,"duplicates":45,"related":46,"reserved_at":9,"published_at":49,"modified_at":50,"state":51,"summary":52,"references_raw":60,"kevs":103,"epss":104,"epss_history":107,"metrics":368,"affected":377},"CVE-2016-9137","Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that is mishandled during __wakeup processing.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[21],{"_key":22,"name":23,"source":24,"url":25,"maturity":26,"reliability_score":27,"verified":28,"type":9,"platforms":29,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_53E481C9AFE343BD","Exploit Reference (bugs.php.net)","reference","https://bugs.php.net/bug.php?id=73147","unknown",0.2,false,[],[],[],[33,35,37,39,41,43],{"_key":34},"SUSE-SU-2016:2941-1",{"_key":36},"SUSE-SU-2016:2975-1",{"_key":38},"DSA-3698-1",{"_key":40},"UBUNTU-CVE-2016-9137",{"_key":42},"USN-3196-1",{"_key":44},"USN-3211-1",[],[47,48],{"_key":34},{"_key":36},"2017-01-04T20:00:00.000Z","2024-08-06T02:42:10.922Z","Modified",{"cisa_kev":28,"cisa_ransomware":28,"cisa_vendor":9,"epss_severity":53,"epss_score":54,"severity":55,"severity_score":56,"severity_version":57,"severity_source":58,"severity_vector":59,"severity_status":51},"low",0.00942,"critical",9.8,"v3.0","nvd","CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[61,68,73,77,81,88,94,98],{"url":25,"sources":62,"tags":64},[63,58],"cve.org",[65,66,67],"X Refsource CONFIRM","Exploit","Vendor Advisory",{"url":69,"sources":70,"tags":71},"http://www.php.net/ChangeLog-7.php",[63,58],[65,72,67],"Release Notes",{"url":74,"sources":75,"tags":76},"http://www.php.net/ChangeLog-5.php",[63,58],[65,72,67],{"url":78,"sources":79,"tags":80},"https://www.tenable.com/security/tns-2016-19",[63,58],[65],{"url":82,"sources":83,"tags":84},"http://www.securityfocus.com/bid/93577",[63,58],[85,86,87],"VDB Entry","X Refsource BID","Third Party Advisory",{"url":89,"sources":90,"tags":91},"http://www.openwall.com/lists/oss-security/2016/11/01/2",[63,58],[92,93,87],"Mailing List","X Refsource MLIST",{"url":95,"sources":96,"tags":97},"http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=0e6fe3a4c96be2d3e88389a5776f878021b4c59f",[63,58],[65],{"url":99,"sources":100,"tags":101},"http://www.debian.org/security/2016/dsa-3698",[63,58],[67,102],"X Refsource DEBIAN",[],{"date":105,"score":54,"percentile":106},"2026-06-04",0.76624,[108,111,114,117,120,122,125,128,131,134,137,140,143,146,148,151,154,157,160,163,166,168,171,174,177,180,183,186,189,192,195,197,199,202,204,207,210,213,216,219,222,225,228,231,234,237,240,243,246,249,252,255,258,261,265,268,271,274,277,280,283,286,289,292,295,298,301,304,307,310,313,315,318,321,324,326,329,331,334,337,340,343,346,349,352,354,357,360,363,365],{"date":109,"score":54,"percentile":110},"2025-11-04",0.75496,{"date":112,"score":54,"percentile":113},"2025-11-05",0.75491,{"date":115,"score":54,"percentile":116},"2025-11-06",0.75487,{"date":118,"score":54,"percentile":119},"2025-11-07",0.75501,{"date":121,"score":54,"percentile":119},"2025-11-08",{"date":123,"score":54,"percentile":124},"2025-11-09",0.755,{"date":126,"score":54,"percentile":127},"2025-11-10",0.75488,{"date":129,"score":54,"percentile":130},"2025-11-11",0.75492,{"date":132,"score":54,"percentile":133},"2025-11-12",0.75512,{"date":135,"score":54,"percentile":136},"2025-11-13",0.75519,{"date":138,"score":54,"percentile":139},"2025-11-14",0.75524,{"date":141,"score":54,"percentile":142},"2025-11-15",0.75521,{"date":144,"score":54,"percentile":145},"2025-11-16",0.7552,{"date":147,"score":54,"percentile":133},"2025-11-17",{"date":149,"score":54,"percentile":150},"2025-11-18",0.74277,{"date":152,"score":54,"percentile":153},"2025-11-19",0.74286,{"date":155,"score":54,"percentile":156},"2025-11-20",0.74295,{"date":158,"score":54,"percentile":159},"2025-11-21",0.75542,{"date":161,"score":54,"percentile":162},"2025-11-22",0.75541,{"date":164,"score":54,"percentile":165},"2025-11-23",0.75526,{"date":167,"score":54,"percentile":139},"2025-11-24",{"date":169,"score":54,"percentile":170},"2025-11-25",0.75529,{"date":172,"score":54,"percentile":173},"2025-11-26",0.75537,{"date":175,"score":54,"percentile":176},"2025-11-27",0.75539,{"date":178,"score":54,"percentile":179},"2025-11-28",0.75528,{"date":181,"score":54,"percentile":182},"2025-11-29",0.7553,{"date":184,"score":54,"percentile":185},"2025-11-30",0.75527,{"date":187,"score":54,"percentile":188},"2025-12-01",0.75655,{"date":190,"score":54,"percentile":191},"2025-12-02",0.75662,{"date":193,"score":54,"percentile":194},"2025-12-03",0.75649,{"date":196,"score":54,"percentile":136},"2025-12-04",{"date":198,"score":54,"percentile":185},"2025-12-05",{"date":200,"score":54,"percentile":201},"2025-12-06",0.75531,{"date":203,"score":54,"percentile":170},"2025-12-07",{"date":205,"score":54,"percentile":206},"2025-12-08",0.75534,{"date":208,"score":54,"percentile":209},"2025-12-09",0.75561,{"date":211,"score":54,"percentile":212},"2025-12-10",0.7559,{"date":214,"score":54,"percentile":215},"2025-12-11",0.75607,{"date":217,"score":54,"percentile":218},"2025-12-12",0.75631,{"date":220,"score":54,"percentile":221},"2025-12-13",0.75634,{"date":223,"score":54,"percentile":224},"2025-12-14",0.7563,{"date":226,"score":54,"percentile":227},"2025-12-15",0.75629,{"date":229,"score":54,"percentile":230},"2025-12-16",0.75641,{"date":232,"score":54,"percentile":233},"2025-12-17",0.75652,{"date":235,"score":54,"percentile":236},"2025-12-18",0.75673,{"date":238,"score":54,"percentile":239},"2025-12-19",0.75689,{"date":241,"score":54,"percentile":242},"2025-12-20",0.75684,{"date":244,"score":54,"percentile":245},"2025-12-21",0.75678,{"date":247,"score":54,"percentile":248},"2025-12-22",0.7568,{"date":250,"score":54,"percentile":251},"2025-12-23",0.75677,{"date":253,"score":54,"percentile":254},"2025-12-24",0.75687,{"date":256,"score":54,"percentile":257},"2025-12-25",0.7571,{"date":259,"score":54,"percentile":260},"2025-12-26",0.75708,{"date":262,"score":263,"percentile":264},"2025-12-27",0.00889,0.7501,{"date":266,"score":54,"percentile":267},"2025-12-28",0.75693,{"date":269,"score":54,"percentile":270},"2025-12-29",0.7569,{"date":272,"score":54,"percentile":273},"2025-12-30",0.75702,{"date":275,"score":54,"percentile":276},"2025-12-31",0.75722,{"date":278,"score":54,"percentile":279},"2026-01-01",0.75863,{"date":281,"score":54,"percentile":282},"2026-01-02",0.75867,{"date":284,"score":54,"percentile":285},"2026-01-03",0.75866,{"date":287,"score":54,"percentile":288},"2026-01-04",0.75733,{"date":290,"score":54,"percentile":291},"2026-01-05",0.75724,{"date":293,"score":54,"percentile":294},"2026-01-06",0.75739,{"date":296,"score":54,"percentile":297},"2026-01-07",0.75748,{"date":299,"score":54,"percentile":300},"2026-01-08",0.75761,{"date":302,"score":54,"percentile":303},"2026-01-09",0.75767,{"date":305,"score":54,"percentile":306},"2026-01-10",0.75769,{"date":308,"score":54,"percentile":309},"2026-01-11",0.75753,{"date":311,"score":54,"percentile":312},"2026-01-12",0.7574,{"date":314,"score":54,"percentile":312},"2026-01-13",{"date":316,"score":54,"percentile":317},"2026-01-14",0.75768,{"date":319,"score":54,"percentile":320},"2026-01-15",0.75775,{"date":322,"score":54,"percentile":323},"2026-01-16",0.75786,{"date":325,"score":54,"percentile":323},"2026-01-17",{"date":327,"score":54,"percentile":328},"2026-01-18",0.75779,{"date":330,"score":54,"percentile":320},"2026-01-19",{"date":332,"score":54,"percentile":333},"2026-01-20",0.75776,{"date":335,"score":54,"percentile":336},"2026-01-21",0.7578,{"date":338,"score":54,"percentile":339},"2026-01-22",0.75785,{"date":341,"score":54,"percentile":342},"2026-01-23",0.75812,{"date":344,"score":54,"percentile":345},"2026-01-24",0.7582,{"date":347,"score":54,"percentile":348},"2026-01-25",0.75808,{"date":350,"score":54,"percentile":351},"2026-01-26",0.75807,{"date":353,"score":54,"percentile":348},"2026-01-27",{"date":355,"score":54,"percentile":356},"2026-01-28",0.75816,{"date":358,"score":54,"percentile":359},"2026-01-29",0.75813,{"date":361,"score":54,"percentile":362},"2026-01-30",0.75819,{"date":364,"score":54,"percentile":362},"2026-01-31",{"date":366,"score":54,"percentile":367},"2026-02-01",0.75944,[369],{"source":58,"cvss_v2_0":370,"cvss_v3_0":375,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":371,"baseSeverity":9,"vectorString":372,"impactScore":373,"exploitabilityScore":374},7.5,"AV:N/AC:L/Au:N/C:P/I:P/A:P",6.4,10,{"baseScore":56,"baseSeverity":376,"vectorString":59,"impactScore":56,"exploitabilityScore":374},"CRITICAL",[378],{"ecosystem":9,"name":379,"vendor":9,"product":379,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":380},"PHP",[381,387,389,391,393,395,397,399,401,403,405,407,409],{"version":382,"is_range":383,"range_type":384,"version_start":9,"version_start_type":9,"version_end":385,"version_end_type":386,"fixed_in":9},"lte5.6.26",true,"cpe","5.6.26","including",{"version":388,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.0",{"version":390,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.1",{"version":392,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.2",{"version":394,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.3",{"version":396,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.4",{"version":398,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.5",{"version":400,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.6",{"version":402,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.7",{"version":404,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.8",{"version":406,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.9",{"version":408,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.10",{"version":410,"is_range":28,"range_type":384,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.11"]