littlecms kayıtları
littlecms üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %80
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-787 Out-of-bounds Write3
- CWE-190 Integer Overflow or Wraparound2
- CWE-189 Numeric Errors1
- CWE-20 Improper Input Validation1
- CWE-401 Missing Release of Memory after Effective Lifetime1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2013-7455İstismar yok | Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers tlittlecms · little cms color engine | Kritik9,8 | — | %6,2 | 7 May 2016 |
41Planlayın | CVE-2008-5316İstismar yok | Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to halittlecms · lcms · CWE-119 | Kritik10,0 | — | %2,8 | 3 Ara 2008 |
41Planlayın | CVE-2008-5317İstismar yok | Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers littlecms · lcms · CWE-189 | Kritik10,0 | — | %2,2 | 3 Ara 2008 |
39İzleyin | CVE-2007-2741İstismar yok | Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service littlecms · lcms · CWE-119 | Kritik9,3 | — | %7,9 | 17 May 2007 |
39İzleyin | CVE-2009-0733İstismar yok | Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefolittlecms · little cms · CWE-787 | Kritik9,3 | — | %5,5 | 23 Mar 2009 |
39İzleyin | CVE-2009-0723İstismar yok | Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow contextgimp · gimp · CWE-190 | Kritik9,3 | — | %5,0 | 23 Mar 2009 |
31İzleyin | CVE-2018-11556İstismar yok | tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a craftelittlecms · little cms · CWE-787 | Yüksek7,8 | — | %1,1 | 30 May 2018 |
31İzleyin | CVE-2018-11555İstismar yok | tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file.littlecms · little cms · CWE-787 | Yüksek7,8 | — | %1,1 | 30 May 2018 |
30İzleyin | CVE-2026-41254İstismar yok | Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplicalittlecms · little cms · CWE-696 | Yüksek7,5 | — | %0,4 | 18 Nis 2026 |
29İzleyin | CVE-2016-10165İstismar yok | The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a deniallittlecms · little cms color engine · CWE-125 | Yüksek7,1 | — | %2,8 | 3 Şub 2017 |
23İzleyin | CVE-2018-16435İstismar yok | Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heaplittlecms · little cms color engine · CWE-190 | Orta5,5 | — | %1,7 | 3 Eyl 2018 |
21İzleyin | CVE-2013-4160İstismar yok | Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL littlecms · little cms color engine | Orta5,0 | — | %2,8 | 21 Oca 2014 |
18İzleyin | CVE-2009-0793İstismar yok | cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of servlittlecms · lcms · CWE-20 | Orta4,3 | — | %4,8 | 9 Nis 2009 |
18İzleyin | CVE-2013-4276İstismar yok | Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of serviclittlecms · little cms color engine · CWE-119 | Orta4,3 | — | %4,0 | 28 Eyl 2013 |
18İzleyin | CVE-2009-0581İstismar yok | Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attlittlecms · little cms · CWE-401 | Orta4,3 | — | %2,5 | 23 Mar 2009 |
- CVE-2013-745541Planlayın
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers t
KritikCVSS 9,8İstismar yokEPSS %6littlecms · little cms color engine7 May 2016
- CVE-2008-531641Planlayın
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to ha
KritikCVSS 10,0İstismar yokEPSS %3littlecms · lcms3 Ara 2008
- CVE-2008-531741Planlayın
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers
KritikCVSS 10,0İstismar yokEPSS %2littlecms · lcms3 Ara 2008
- CVE-2007-274139İzleyin
Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service
KritikCVSS 9,3İstismar yokEPSS %8littlecms · lcms17 May 2007
- CVE-2009-073339İzleyin
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefo
KritikCVSS 9,3İstismar yokEPSS %6littlecms · little cms23 Mar 2009
- CVE-2009-072339İzleyin
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context
KritikCVSS 9,3İstismar yokEPSS %5gimp · gimp23 Mar 2009
- CVE-2018-1155631İzleyin
tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafte
YüksekCVSS 7,8İstismar yokEPSS %1littlecms · little cms30 May 2018
- CVE-2018-1155531İzleyin
tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file.
YüksekCVSS 7,8İstismar yokEPSS %1littlecms · little cms30 May 2018
- CVE-2026-4125430İzleyin
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplica
YüksekCVSS 7,5İstismar yokEPSS %0littlecms · little cms18 Nis 2026
- CVE-2016-1016529İzleyin
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial
YüksekCVSS 7,1İstismar yokEPSS %3littlecms · little cms color engine3 Şub 2017
- CVE-2018-1643523İzleyin
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap
OrtaCVSS 5,5İstismar yokEPSS %2littlecms · little cms color engine3 Eyl 2018
- CVE-2013-416021İzleyin
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL
OrtaCVSS 5,0İstismar yokEPSS %3littlecms · little cms color engine21 Oca 2014
- CVE-2009-079318İzleyin
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of serv
OrtaCVSS 4,3İstismar yokEPSS %5littlecms · lcms9 Nis 2009
- CVE-2013-427618İzleyin
Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of servic
OrtaCVSS 4,3İstismar yokEPSS %4littlecms · little cms color engine28 Eyl 2013
- CVE-2009-058118İzleyin
Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent att
OrtaCVSS 4,3İstismar yokEPSS %3littlecms · little cms23 Mar 2009