Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Little Cms HIGH 7.5
CVE-2026-41254

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Fix: after 2.18
Fix from $1,950 2026-04-18
Little Cms HIGH 7.8
CVE-2018-11555

tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Lit…

Mitigation only
Fix from $1,950 2018-05-30
Little Cms HIGH 7.8
CVE-2018-11556

tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF fi…

Mitigation only
Fix from $1,950 2018-05-30
Little Cms Color Engine CRITICAL 9.8
CVE-2013-7455EPSS 6%

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute…

Patch available
Fix from $2,300 2016-05-07
Little Cms Color Engine MEDIUM 5.0
CVE-2013-4160

Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer d…

Fix: after 2.4
Fix from $1,600 2014-01-21
Lcms HIGH 10.0
CVE-2008-5316

Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unk…

Fix: after 1.15
Fix from $1,950 2008-12-03
Lcms HIGH 10.0
CVE-2008-5317

Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have a…

Fix: after 1.16
Fix from $1,950 2008-12-03
Lcms HIGH 9.3
CVE-2007-2741EPSS 8%

Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (applicat…

Fix: after 1.14
Fix from $1,950 2007-05-17