AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-3515

HIGH · CVSS 7.5 EPSS 30.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-07-09 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2014-3515
Severity
HIGH
CVSS
7.5
EPSS
30.13%

Original Filing — NVD Description

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.