VYPR
High severity7.5NVD Advisory· Published May 31, 2013· Updated Apr 29, 2026

CVE-2013-3735

CVE-2013-3735

Description

The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted function definition, as demonstrated by an attack within a shared web-hosting environment. NOTE: the vendor's http://php.net/security-note.php page says "for critical security situations you should be using OS-level security by running multiple web servers each as their own user id.

Affected products

30
  • PHP/PHP30 versions
    cpe:2.3:a:php:php:*:rc1:*:*:*:*:*:*+ 29 more
    • cpe:2.3:a:php:php:*:rc1:*:*:*:*:*:*range: <=5.4.15
    • cpe:2.3:a:php:php:5.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.4:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.6:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.8:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.9:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.10:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.11:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.12:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.12:rc1:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.12:rc2:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.13:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.13:rc1:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.14:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.4.14:rc1:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:alpha4:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:alpha5:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:alpha6:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.5.0:beta4:*:*:*:*:*:*

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

4

News mentions

0

No linked articles in our index yet.