← All CVEs

CVE-2015-3330

medium · 6.8

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."

6.8
CVSS
14.1%
EPSS (exploit prob.)
96th
EPSS percentile
2015-06-09
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
oraclelinux6
oraclelinux7
oraclesolaris11.2
applemac_os_x<= 10.10.4
redhatenterprise_linux6.0
redhatenterprise_linux7.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_hpc_node7.0
redhatenterprise_linux_hpc_node_eus7.1
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_eus7.1
redhatenterprise_linux_workstation7.0
phpphp<= 5.4.39
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.0
phpphp5.5.1
phpphp5.5.2
phpphp5.5.3
phpphp5.5.4
phpphp5.5.5
phpphp5.5.6
phpphp5.5.7
phpphp5.5.8
phpphp5.5.9
phpphp5.5.10
phpphp5.5.11
phpphp5.5.12
phpphp5.5.13
phpphp5.5.14

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-3330