peter bassill · operator
$ cve CVE-2015-6834 JSON

CVE-2015-6834 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 46.8% (pctl 99)

Patch early

A public exploit exists.

Description

Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3) the SplDoublyLinkedList class, which are mishandled during unserialization.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS46.8% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2016-05-16
Last modified2026-06-17

Affected (1)

VendorProduct
phpphp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD