{"api_version":"1","generated_at":"2026-07-23T07:15:04+00:00","cve":"CVE-2015-6831","urls":{"html":"https://cve.report/CVE-2015-6831","api":"https://cve.report/api/cve/CVE-2015-6831.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-6831","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-6831"},"summary":{"title":"CVE-2015-6831","description":"Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.","state":"PUBLISHED","assigner":"microfocus","published_at":"2016-01-19 05:59:02","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-416","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://bugs.php.net/bug.php?id=70169","name":"https://bugs.php.net/bug.php?id=70169","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP :: Sec Bug #70169 :: Use After Free Vulnerability in unserialize() with SplDoublyLinkedList","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201606-10","name":"https://security.gentoo.org/glsa/201606-10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP: Multiple vulnerabilities (GLSA 201606-10) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2015/08/19/3","name":"http://www.openwall.com/lists/oss-security/2015/08/19/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE Request: more php unserializing issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.php.net/bug.php?id=70166","name":"https://bugs.php.net/bug.php?id=70166","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP :: Sec Bug #70166 :: Use After Free Vulnerability in unserialize() with SPLArrayObject","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2015/dsa-3344","name":"http://www.debian.org/security/2015/dsa-3344","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3344-1 php5","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.php.net/bug.php?id=70155","name":"https://bugs.php.net/bug.php?id=70155","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP :: Sec Bug #70155 :: Use After Free Vulnerability in unserialize() with SPLArrayObject","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/76737","name":"http://www.securityfocus.com/bid/76737","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP CVE-2015-6831 Multiple Use After Free Remote Code Execution Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.php.net/ChangeLog-5.php","name":"http://www.php.net/ChangeLog-5.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP: PHP 5 ChangeLog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.php.net/bug.php?id=70168","name":"https://bugs.php.net/bug.php?id=70168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP :: Sec Bug #70168 :: Use After Free Vulnerability in unserialize() with SplObjectStorage","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-6831","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-6831","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"6831","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T07:36:33.268Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"DSA-3344","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2015/dsa-3344"},{"name":"76737","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/76737"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.php.net/bug.php?id=70169"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.php.net/bug.php?id=70168"},{"name":"[oss-security] 20150819 CVE Request: more php unserializing issues","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2015/08/19/3"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.php.net/ChangeLog-5.php"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.php.net/bug.php?id=70166"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.php.net/bug.php?id=70155"},{"name":"GLSA-201606-10","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201606-10"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-08-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2021-01-06T16:15:25.000Z","orgId":"f81092c5-7f14-476d-80dc-24857f90be84","shortName":"microfocus"},"references":[{"name":"DSA-3344","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2015/dsa-3344"},{"name":"76737","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/76737"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.php.net/bug.php?id=70169"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.php.net/bug.php?id=70168"},{"name":"[oss-security] 20150819 CVE Request: more php unserializing issues","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2015/08/19/3"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.php.net/ChangeLog-5.php"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.php.net/bug.php?id=70166"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.php.net/bug.php?id=70155"},{"name":"GLSA-201606-10","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201606-10"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@microfocus.com","ID":"CVE-2015-6831","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"DSA-3344","refsource":"DEBIAN","url":"http://www.debian.org/security/2015/dsa-3344"},{"name":"76737","refsource":"BID","url":"http://www.securityfocus.com/bid/76737"},{"name":"https://bugs.php.net/bug.php?id=70169","refsource":"CONFIRM","url":"https://bugs.php.net/bug.php?id=70169"},{"name":"https://bugs.php.net/bug.php?id=70168","refsource":"CONFIRM","url":"https://bugs.php.net/bug.php?id=70168"},{"name":"[oss-security] 20150819 CVE Request: more php unserializing issues","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/08/19/3"},{"name":"http://www.php.net/ChangeLog-5.php","refsource":"CONFIRM","url":"http://www.php.net/ChangeLog-5.php"},{"name":"https://bugs.php.net/bug.php?id=70166","refsource":"CONFIRM","url":"https://bugs.php.net/bug.php?id=70166"},{"name":"https://bugs.php.net/bug.php?id=70155","refsource":"CONFIRM","url":"https://bugs.php.net/bug.php?id=70155"},{"name":"GLSA-201606-10","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201606-10"}]}}}},"cveMetadata":{"assignerOrgId":"f81092c5-7f14-476d-80dc-24857f90be84","assignerShortName":"microfocus","cveId":"CVE-2015-6831","datePublished":"2016-01-19T02:00:00.000Z","dateReserved":"2015-09-08T00:00:00.000Z","dateUpdated":"2024-08-06T07:36:33.268Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-01-19 05:59:02","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-416","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":3.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionEndExcluding":"5.4.44","matchCriteriaId":"A03A31A6-4CAC-4229-A1E4-FDC785765646"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5.0","versionEndExcluding":"5.5.28","matchCriteriaId":"B9C0D35D-0789-471F-9252-FB4233D7E1F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6.0","versionEndExcluding":"5.6.12","matchCriteriaId":"C946BEC6-918B-4C3F-9D2C-5FE90F693A2E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"16F59A04-14CF-49E2-9973-645477EA09DA"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"6831","Ordinal":"1","Title":"CVE-2015-6831","CVE":"CVE-2015-6831","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"6831","Ordinal":"1","NoteData":"Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.","Type":"Description","Title":"CVE-2015-6831"},{"CveYear":"2015","CveId":"6831","Ordinal":"2","NoteData":"2016-01-18","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"6831","Ordinal":"3","NoteData":"2021-01-06","Type":"Other","Title":"Modified"}]}}}