9.8
CVSSv3

CVE-2015-4116

Published: 16/05/2016 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP prior to 5.5.27 and 5.6.x prior to 5.6.11 allows remote malicious users to execute arbitrary code by triggering a failed SplMinHeap::compare operation.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse leap 42.1

php php 5.6.1

php php 5.6.5

php php 5.6.0

php php 5.6.4

php php 5.6.6

php php 5.6.2

php php 5.6.10

php php 5.6.7

php php

php php 5.6.9

php php 5.6.3

php php 5.6.8

Vendor Advisories

Several security issues were fixed in PHP ...
Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heapc in PHP before 5527 and 56x before 5611 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation ...