Skip to main content

Vendor/product archive

littlecms / little_cms CVEs

Beta · best-effort

6 CVEs tagged to littlecms / little_cms2 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-41254

Published Apr 18, 2026

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

CVSS 4.0 · Medium
evidence mentions
7
Buzz score
38.8
Vendor/product tagsBeta · best-effort

CVE-2018-11556

Published May 30, 2018

tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developer…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11555

Published May 30, 2018

tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1