CVE-2014-3622: PHP
Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.
Affected products
- PHP PHP: from 5.6.0, before 5.6.1 (fixed in 5.6.1)
Published 2020-02-19. Last modified 2026-06-17.