Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2009-0733
Disclosure Date: March 23, 2009 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.
0
Attacker Value
Unknown
CVE-2008-5628
Disclosure Date: December 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands via the term parameter.
0
Attacker Value
Unknown
CVE-2008-5317
Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
0
Attacker Value
Unknown
CVE-2008-5316
Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.
0
Attacker Value
Unknown
CVE-2008-3036
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. (dot dot) in the template parameter.
0
Attacker Value
Unknown
CVE-2007-2741
Disclosure Date: May 17, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.
0