Metrics
Affected Vendors & Products
Wed, 30 Apr 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Php
Php php |
|
CPEs | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | |
Vendors & Products |
Php
Php php |
|
Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 07 Apr 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Fri, 04 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 04 Apr 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??= operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution. | |
Title | Reference counting in php_request_shutdown causes Use-After-Free | |
Weaknesses | CWE-416 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: php
Published: 2025-04-04T17:51:07.550Z
Updated: 2025-04-05T03:55:36.686Z
Reserved: 2024-11-15T06:26:33.249Z
Link: CVE-2024-11235

Updated: 2025-04-04T19:50:12.693Z

Status : Analyzed
Published: 2025-04-04T18:15:48.020
Modified: 2025-04-30T19:25:17.507
Link: CVE-2024-11235
