CVE-2026-41254
- EPSS 0.03%
- Veröffentlicht 18.04.2026 06:43:13
- Zuletzt bearbeitet 07.05.2026 18:16:19
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
CVE-2018-11555
- EPSS 0.2%
- Veröffentlicht 30.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:36
tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program u...
CVE-2018-11556
- EPSS 0.2%
- Veröffentlicht 30.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:36
tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sam...
CVE-2009-0581
- EPSS 1.89%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 23.04.2026 00:35:47
Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.
CVE-2009-0723
- EPSS 0.86%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer over...
CVE-2009-0733
- EPSS 1.87%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image ...