AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-4604

HIGH · CVSS 7.5 EPSS 7.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-05-16 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2015-4604
Severity
HIGH
CVSS
7.5
EPSS
7.39%

Original NVD Description

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.