IsItPatchedInstant security status for any software version
← All products

CVE-2014-3515

HIGH severity · CVSS 7.5
7.5CVSS HIGH

Summary

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges required
User interaction
Confidentiality impact
Integrity impact
Availability impact
Exploit probability (EPSS)49%

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products we track (2)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Last checked: Wed, 10 Jun 2026 22:18:30 UTC