Lucene search

K
cve[email protected]CVE-2014-9425
HistoryDec 31, 2014 - 2:59 a.m.

CVE-2014-9425

2014-12-3102:59:00
web.nvd.nist.gov
57
2
cve-2014-9425
zend engine
php
vulnerability
denial of service
remote attackers

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.7 High

AI Score

Confidence

High

0.063 Low

EPSS

Percentile

93.7%

Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

Affected configurations

NVD
Node
phpphpRange5.5.20
OR
phpphpRange5.6.05.6.4
Node
applemac_os_xRange10.10.5
CPENameOperatorVersion
php:phpphple5.5.20
php:phpphple5.6.4

Social References

More

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.7 High

AI Score

Confidence

High

0.063 Low

EPSS

Percentile

93.7%