AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2015-4605

HIGH · CVSS 7.5 EPSS 7.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-05-16 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2015-4605
Severity
HIGH
CVSS
7.5
EPSS
7.39%

Original Filing — NVD Description

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.