Where
-Infinity
0

Vendor Risk Score

See how littlecms compares to other vendors in security performance

View Risk Score →
Severity
7.5
Integer Overflow
AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

Last updated 2 June 2026

1 / 2
Source: Ubuntu
First published (updated )
Severity
9.3
Buffer Overflow
AV:N/AC:M/Au:N/C:C/I:C/A:C

Chris Evans discovered a flaw in how LittleCms checks certain upper-bounds sizes. This flaw could potentially lead to arbitrary code execution in applications that use the system LittleCms library, or embed the source into their application.

Acknowledgements:

Red Hat would like to thank Chris Evans from the Google Security Team for reporting these issues.

1 / 2
Source: Red Hat
First published (updated )
Severity
9.3
Integer Overflow, Buffer Overflow
AV:N/AC:M/Au:N/C:C/I:C/A:C

Chris Evans discovered an integer overflow flaw in LittleCms. This flaw could potentially lead to arbitrary code execution in applications that use the system LittleCms library, or embed the source into their application.

Acknowledgements:

Red Hat would like to thank Chris Evans from the Google Security Team for reporting these issues.

1 / 2
Source: Red Hat
First published (updated )
Severity
4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P

Chris Evans discovered a memory leak flaw in LittleCms. This flaw could cause applications that use the system LittleCms library, or embed the source into their application, to crash.

Acknowledgements:

Red Hat would like to thank Chris Evans from the Google Security Team for reporting this issue.

1 / 2
Source: Red Hat
First published (updated )
Severity
7.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

An out-of-bounds read in cmstypes.c in TypeMLURead function was found, leading to heap memory leak triggered by crafted ICC profile.

Upstream patch:

https://github.com/mm2/Little-CMS/commit/5ca71a7bc18b6897ab21d815d15e218e204581e2

CVE request:

http://seclists.org/oss-sec/2016/q3/288

1 / 3
Source: Red Hat
First published (updated )
Severity
4.3
Buffer Overflow
AV:N/AC:M/Au:N/C:N/I:N/A:P

Last updated 24 July 2024

1 / 3
Source: Ubuntu
First published (updated )
Severity
5.5
Integer Overflow, Buffer Overflow
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

A flaw was found in Little CMS (aka Little Color Management System) 2.9. An integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

References: https://github.com/mm2/Little-CMS/issues/171

Upstream Fix: https://github.com/mm2/Little-CMS/commit/768f70ca405cd3159d990e962d54456773bb8cf8

1 / 3
Source: Red Hat
First published (updated )
Severity
9.3
Buffer Overflow
AV:N/AC:M/Au:N/C:C/I:C/A:C

Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.

First published (updated )
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.

First published (updated )
Severity
4.3
Input Validation, Null Pointer Dereference
AV:N/AC:M/Au:N/C:N/I:N/A:P

cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."

First published (updated )
Severity
10
Double Free
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

First published (updated )
Severity
5
Null Pointer Dereference
AV:N/AC:L/Au:N/C:N/I:N/A:P

Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.

First published (updated )
Severity
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

DISPUTED tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”.

1 / 2
First published (updated )
Severity
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

DISPUTED tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”.

1 / 2
First published (updated )
Severity
1

Chris Evans discovered a memory leak flaw in LittleCms. This flaw could cause applications that use the system LittleCms library, or embed the source into their application, to crash.

Acknowledgements:

Red Hat would like to thank Chris Evans from the Google Security Team for reporting this issue.

First published (updated )
Severity
4
Integer Overflow

Chris Evans discovered an integer overflow flaw in LittleCms. This flaw could potentially lead to arbitrary code execution in applications that use the system LittleCms library, or embed the source into their application.

Acknowledgements:

Red Hat would like to thank Chris Evans from the Google Security Team for reporting these issues.

First published (updated )
Severity
4

Chris Evans discovered a flaw in how LittleCms checks certain upper-bounds sizes. This flaw could potentially lead to arbitrary code execution in applications that use the system LittleCms library, or embed the source into their application.

Acknowledgements:

Red Hat would like to thank Chris Evans from the Google Security Team for reporting these issues.

First published (updated )
Severity
4
Buffer Overflow

Three (two in ColorSpace conversion calculator, one in TIFF compare utility) stack-based buffer overflow flaws were found in the way icctrans / tiffdiff tools of LittleCMS, the color management system, used to process certain ICC color profile / TIFF image format files. Remote attacker could provide a specially-crafted ICC color profile / TIFF image format files that, when opened in color space conversion calculator (icctrans) or TIFF compare utility (tiffdiff) of LittleCMS would lead to that utility crash.

References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=718682 [2] http://www.openwall.com/lists/oss-security/2013/08/05/2

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203