CVE-2016-3141

CRITICAL

Apple Mac OS X < 10.11.4 - Memory Corruption

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-3141. PoCs published by peternguyen93.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2016-3141, a use-after-free vulnerability in PHP's WDDX extension. The exploit demonstrates memory corruption leading to remote code execution by manipulating heap structures.

Description

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

Exploits (1)

nomisec WORKING POC 15 stars
by peternguyen93 · poc
https://github.com/peternguyen93/CVE-2016-3141

This repository contains a functional exploit for CVE-2016-3141, a use-after-free vulnerability in PHP's WDDX extension. The exploit demonstrates memory corruption leading to remote code execution by manipulating heap structures.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: PHP before 5.5.33 and 5.6.x before 5.6.19
No auth needed
Prerequisites: PHP with WDDX extension enabled · Ability to send crafted XML data to a PHP application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (15)

Core 15
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2750.html
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/May/msg00004.html
Various Sources x_refsource_confirm
https://php.net/ChangeLog-5.php
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2952-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/84271
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206567
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2952-2
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035255
Various Sources x_refsource_confirm
https://bugs.php.net/bug.php?id=71587

Scores

CVSS v3 9.8
EPSS 0.7228
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (21)
apple/mac_os_x < 10.11.4
php/php 5.6.0
php/php 5.6.1
php/php 5.6.2
php/php 5.6.3
php/php 5.6.4
php/php 5.6.5
php/php 5.6.6
php/php 5.6.7
php/php 5.6.8
... and 11 more
Published Mar 31, 2016
Tracked Since Feb 18, 2026