CVE-2016-7134

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.


We have discovered 2,122,717 live websites that are affected by CVE-2016-7134.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains2,122,717 live websites (24.32% of PHP install base)
Vulnerable Versions
  • from 0 before 7.0.10
Vulnerable Versions Count258 versions ( 47.17% of all versions)



Details

  • Published - Sep 12, 2016
  • Updated - Aug 6, 2024

CVE-2016-7134 usage by Country

United States527,388 websites



Russia238,261 websites
France159,390 websites
Germany150,273 websites
Japan125,782 websites
Taiwan113,294 websites
Netherlands85,765 websites
China75,987 websites
GB44,045 websites
Poland37,443 websites

CVE-2016-7134 usage by TLD

.com898,813 websites
.ru204,147 websites
.de92,434 websites
.net78,367 websites
.nl57,904 websites
.fr57,665 websites
.org57,018 websites
.jp33,584 websites
.pl31,312 websites
.co.uk30,968 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-7134

Top websites that are affected by CVE-2016-7134. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.org China***
*****.***********.com Canada***
**********.com United States***
**********.com United States***
************.***.ar Argentina*,***
*****.ru Russia*,***
********.*********.com Singapore*,***
******************.com United States*,***
***.org United States*,***
*********.******.net United States*,***
See full domain list

FAQ

A total of 2,122,717 websites have been identified as vulnerable to CVE-2016-7134, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2016-7134 vulnerability.
PHP versions before 7.0.10 are vulnerable to CVE-2016-7134.
Version 7.0.10 of PHP addresses the CVE-2016-7134 security vulnerability.