AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-7804

MEDIUM · CVSS 6.8 EPSS 8.80%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-12-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2015-7804
Severity
MEDIUM
CVSS
6.8
EPSS
8.80%

Original NVD Description

Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (uninitialized pointer dereference and application crash) by including the / filename in a .zip PHAR archive.