CVE-2013-7226: PHP
Medium severity, CVSS 6.8. EPSS: 6.7% chance of exploitation in the next 30 days.
Integer overflow in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an imagecrop function call with a large x dimension value, leading to a heap-based buffer overflow.
Affected products
- PHP PHP: version 5.5.0 only; version 5.5.1 only; version 5.5.2 only; version 5.5.3 only; version 5.5.4 only; version 5.5.5 only; …
Published 2014-02-18. Last modified 2026-06-17.