cbcvebase.

Debian Lcms2 vulnerabilities

5 known vulnerabilities affecting debian/lcms2.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2013-7455P3CRITICALCVSS 9.8fixed in lcms2 2.6-1 (bookworm)2013
CVE-2013-7455 [CRITICAL] CVE-2013-7455: lcms2 - Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in lib... Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler. Scope: local bookworm: resolved (fixed in 2.6-1) bullseye: resolved (fixed in 2.6-1) forky: resolved (fixed in 2.6-1) sid
debian
CVE-2016-10165P4HIGHCVSS 7.1fixed in lcms2 2.8-4 (bookworm)2016
CVE-2016-10165 [HIGH] CVE-2016-10165: lcms2 - The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote... The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read. Scope: local bookworm: resolved (fixed in 2.8-4) bullseye: resolved (fixed in 2.8-4) forky: resolved (fixed in 2.8-4) sid: resolved (f
debian
CVE-2014-0459P4LOWCVSS 4.3fixed in lcms2 2.6-1 (bookworm)2014
CVE-2014-0459 [MEDIUM] CVE-2014-0459: lcms2 - Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u5... Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect availability via unknown vectors related to 2D. Scope: local bookworm: resolved (fixed in 2.6-1) bullseye: resolved (fixed in 2.6-1) forky: resolved (fixed in 2.6-1) sid: resolved (fixed in 2.6-1) trixie: resolved (fixed in 2.6-1)
debian
CVE-2018-16435P4MEDIUMCVSS 5.5fixed in lcms2 2.9-3 (bookworm)2018
CVE-2018-16435 [MEDIUM] CVE-2018-16435: lcms2 - Little CMS (aka Little Color Management System) 2.9 has an integer overflow in t... Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile. Scope: local bookworm: resolved (fixed in 2.9-3) bullseye: resolved (fixed in 2.9-3) forky: resolved (fixed in 2.9-3
debian
CVE-2013-4160P4MEDIUMCVSS 5.0fixed in lcms2 2.2+git20110628-2.3 (bookworm)2013
CVE-2013-4160 [MEDIUM] CVE-2013-4160: lcms2 - Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products,... Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed. Scope: local bookworm: resolved (fixed in 2.2+g
debian