CVE-2014-8626: PHP

High severity, CVSS 7.5. EPSS: 5.8% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

Affected products

  • PHP PHP: up to and including 5.2.6; version 5.2.0 only; version 5.2.1 only; version 5.2.2 only; version 5.2.3 only; version 5.2.4 only; …

Published 2014-11-23. Last modified 2026-06-17.