Vulnerability Details CVE-2014-2497
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.138
EPSS Ranking 93.9%
CVSS Severity
CVSS v2 Score 4.3