Skip to main content

Vendor archive

littlecms CVEs

Beta · best-effort

15 CVEs tagged to vendor littlecms6 Critical, 3 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-41254

Published Apr 18, 2026

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

CVSS 4.0 · Medium
evidence mentions
7
Buzz score
38.8
Vendor/product tagsBeta · best-effort

CVE-2018-11556

Published May 30, 2018

tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developer…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11555

Published May 30, 2018

tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7455

Published May 7, 2016

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malforme…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-4160

Published Jan 21, 2014

Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vect…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4276

Published Sep 28, 2013

Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0793

Published Apr 9, 2009

cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and appli…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2741

Published May 17, 2007

Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC p…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1