CVE-2014-9426 describes a memory corruption vulnerability in the apprentice_load function within the Fileinfo component of PHP versions through 5.6.4. This flaw, potentially leading to a denial of service or other unspecified impacts, stems from an attempt to free a stack-based character array. Rated with a CVSS score of 7.3 (High), it has a low attack complexity and no user interaction required, though the vendor disputes the reachability of the vulnerable free operation. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.6.4CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.