cbcvebase.
CVE-2009-0723
published 2009-03-23

CVE-2009-0723: Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent…

PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.03%
91.3th percentile
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

Affected

4 ranges
VendorProductVersion rangeFixed in
gimpgimp< 2.9.22.9.2
littlecmslittle_cms<= 1.17
mozillafirefox
sunopenjdk<= 7

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.