CVE-2014-4698: PHP

Medium severity, CVSS 4.6. EPSS: 0.7% chance of exploitation in the next 30 days.

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applications in certain web-hosting environments.

Affected products

  • PHP PHP: from 5.4.0, before 5.4.32 (fixed in 5.4.32); from 5.5.0, before 5.5.15 (fixed in 5.5.15)

Published 2014-07-10. Last modified 2026-06-17.