CVE Vulnerabilities

CVE-2015-8876

Published: May 22, 2016 | Modified: Feb 14, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger unintended method execution via crafted serialized data.

Affected Software

Name Vendor Start Version End Version
Php Php 5.4.0 (including) 5.4.44 (excluding)
Php Php 5.5.0 (including) 5.5.28 (excluding)
Php Php 5.6.0 (including) 5.6.12 (excluding)

References