Littlecms Lcms vulnerabilities
4 known vulnerabilities affecting littlecms/lcms.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2009-0793MEDIUMCVSS 4.3v1.182009-04-09
CVE-2009-0793 [MEDIUM] CWE-20 CVE-2009-0793: cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows re
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
nvd
CVE-2008-5316CRITICALCVSS 10.0≤ 1.15v1.07+7 more2008-12-03
CVE-2008-5316 [CRITICAL] CVE-2008-5316: Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.
nvd
CVE-2008-5317CRITICALCVSS 10.0≤ 1.16v1.07+8 more2008-12-03
CVE-2008-5317 [CRITICAL] CWE-189 CVE-2008-5317: Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
nvd
CVE-2007-2741CRITICALCVSS 9.3≤ 1.14v1.07+6 more2007-05-17
CVE-2007-2741 [CRITICAL] CWE-119 CVE-2007-2741: Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbi
Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.
nvd