AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2004-0594

MEDIUM · CVSS 5.1 EPSS 54.86%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2004-07-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2004-0594
Severity
MEDIUM
CVSS
5.1
EPSS
54.86%

Original NVD Description

The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.