10
CVE-2008-5317
- EPSS 0.95%
- Published 03.12.2008 17:30:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
Data is provided by the National Vulnerability Database (NVD)
Littlecms ≫ Little Cms Color Engine Version <= 1.16
Littlecms ≫ Little Cms Color Engine Version1.07
Littlecms ≫ Little Cms Color Engine Version1.08
Littlecms ≫ Little Cms Color Engine Version1.09
Littlecms ≫ Little Cms Color Engine Version1.10
Littlecms ≫ Little Cms Color Engine Version1.11
Littlecms ≫ Little Cms Color Engine Version1.12
Littlecms ≫ Little Cms Color Engine Version1.13
Littlecms ≫ Little Cms Color Engine Version1.14
Littlecms ≫ Little Cms Color Engine Version1.15
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.95% | 0.742 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|