Vulnerabilites related to littlecms - lcms
Vulnerability from fkie_nvd
Published
2009-04-09 15:08
Modified
2025-04-09 00:30
Severity ?
Summary
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
References
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:littlecms:lcms:1.18:*:*:*:*:*:*:*", "matchCriteriaId": "1E7E7BA9-CC08-4BC0-9328-15F5B38B6AAB", "vulnerable": true }, { "criteria": "cpe:2.3:a:sun:openjdk:6:*:*:*:*:*:*:*", "matchCriteriaId": "29F1742B-2BFA-4263-9053-B34EE83D8276", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for \"transformations of monochrome profiles.\"" }, { "lang": "es", "value": "cmsxform.c en LittleCMS (tambi\u00e9n conocido como lcms o liblcms) v1.18, con el utilizado en OpenJDK y otros productos, permite a atacantes remotos provocar una denegaci\u00f3n de servicio (desreferenciaci\u00f3n de puntero nulo y ca\u00edda de aplicaci\u00f3n) a trav\u00e9s de una imagen manipulada que provoca la ejecuci\u00f3n de c\u00f3digo incorrecto para \"transformaci\u00f3n de perfiles monocromos\"." } ], "id": "CVE-2009-0793", "lastModified": "2025-04-09T00:30:58.490", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ] }, "published": "2009-04-09T15:08:35.640", "references": [ { "source": "secalert@redhat.com", "url": "http://secunia.com/advisories/34623" }, { "source": "secalert@redhat.com", "url": "http://secunia.com/advisories/34632" }, { "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/34634" }, { "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/34635" }, { "source": "secalert@redhat.com", "url": "http://secunia.com/advisories/34675" }, { "source": "secalert@redhat.com", "url": "http://secunia.com/advisories/34782" }, { "source": "secalert@redhat.com", "url": "http://secunia.com/advisories/35048" }, { "source": "secalert@redhat.com", "url": "http://secunia.com/advisories/42870" }, { "source": "secalert@redhat.com", "url": "http://security.gentoo.org/glsa/glsa-200904-19.xml" }, { "source": "secalert@redhat.com", "url": "http://www.debian.org/security/2009/dsa-1769" }, { "source": "secalert@redhat.com", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:121" }, { "source": "secalert@redhat.com", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" }, { "source": "secalert@redhat.com", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" }, { "source": "secalert@redhat.com", "url": "http://www.securityfocus.com/bid/34411" }, { "source": "secalert@redhat.com", "url": "http://www.securityfocus.com/bid/34420" }, { "source": "secalert@redhat.com", "url": "http://www.ubuntu.com/usn/USN-1043-1" }, { "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2009/0963" }, { "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2009/0964" }, { "source": "secalert@redhat.com", "url": "http://www.vupen.com/english/advisories/2011/0087" }, { "source": "secalert@redhat.com", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=492353" }, { "source": "secalert@redhat.com", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11340" }, { "source": "secalert@redhat.com", "url": "https://rhn.redhat.com/errata/RHSA-2009-0377.html" }, { "source": "secalert@redhat.com", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00203.html" }, { "source": "secalert@redhat.com", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00204.html" }, { "source": "secalert@redhat.com", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00233.html" }, { "source": "secalert@redhat.com", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00285.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/34623" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/34632" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/34634" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/34635" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/34675" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/34782" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/35048" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/42870" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://security.gentoo.org/glsa/glsa-200904-19.xml" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.debian.org/security/2009/dsa-1769" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:121" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/34411" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/34420" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.ubuntu.com/usn/USN-1043-1" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2009/0963" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2009/0964" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.vupen.com/english/advisories/2011/0087" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=492353" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11340" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://rhn.redhat.com/errata/RHSA-2009-0377.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00203.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00204.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00233.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00285.html" } ], "sourceIdentifier": "secalert@redhat.com", "vendorComments": [ { "comment": "Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2009-0793\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, a future lcms packages update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/\n", "lastModified": "2009-04-09T00:00:00", "organization": "Red Hat" } ], "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-20" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2007-05-17 19:30
Modified
2025-04-09 00:30
Severity ?
Summary
Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.
References
Impacted products
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:littlecms:lcms:*:*:*:*:*:*:*:*", "matchCriteriaId": "CABE2C21-19C2-4CDF-8BC0-52DDF7DDF2D9", "versionEndIncluding": "1.14", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.07:*:*:*:*:*:*:*", "matchCriteriaId": "77D8173F-F341-4B34-A50A-388C93CABD01", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.08:*:*:*:*:*:*:*", "matchCriteriaId": "405F539C-0A33-4703-8ADA-AF314EC92B76", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.09:*:*:*:*:*:*:*", "matchCriteriaId": "7DCBA042-6C91-4CDD-96A6-5E99B60519C5", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.10:*:*:*:*:*:*:*", "matchCriteriaId": "C3F25567-8DEF-491C-97F7-D2680115C02E", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.11:*:*:*:*:*:*:*", "matchCriteriaId": "492B453F-5FC7-4B8B-9C42-C911FCA4BFDF", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.12:*:*:*:*:*:*:*", "matchCriteriaId": "CEFA9E7E-B7A9-4106-A480-0E57FCDA7B5F", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.13:*:*:*:*:*:*:*", "matchCriteriaId": "17B723CE-5A76-4DCE-9A2C-EFF32D4A5855", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file." }, { "lang": "es", "value": "Un desbordamiento de b\u00fafer en la regi\u00f3n stack de la memoria en Little CMS (lcms) versiones anteriores a 1.15, permite a atacantes remotos ejecutar c\u00f3digo arbitrario o causar una denegaci\u00f3n de servicio (bloqueo de aplicaci\u00f3n) por medio de un perfil ICC dise\u00f1ado en un archivo JPG." } ], "id": "CVE-2007-2741", "lastModified": "2025-04-09T00:30:58.490", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 9.3, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ] }, "published": "2007-05-17T19:30:00.000", "references": [ { "source": "cve@mitre.org", "url": "http://osvdb.org/36179" }, { "source": "cve@mitre.org", "tags": [ "Exploit" ], "url": "http://scary.beasts.org/security/CESA-2007-001.html" }, { "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ], "url": "http://secunia.com/advisories/25294" }, { "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/27756" }, { "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/32282" }, { "source": "cve@mitre.org", "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:238" }, { "source": "cve@mitre.org", "url": "http://www.novell.com/linux/security/advisories/2007_24_sr.html" }, { "source": "cve@mitre.org", "tags": [ "Exploit", "Patch" ], "url": "http://www.securityfocus.com/bid/24001" }, { "source": "cve@mitre.org", "url": "http://www.ubuntu.com/usn/usn-652-1" }, { "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2007/1837" }, { "source": "cve@mitre.org", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34331" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://osvdb.org/36179" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit" ], "url": "http://scary.beasts.org/security/CESA-2007-001.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Vendor Advisory" ], "url": "http://secunia.com/advisories/25294" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/27756" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/32282" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:238" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.novell.com/linux/security/advisories/2007_24_sr.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit", "Patch" ], "url": "http://www.securityfocus.com/bid/24001" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.ubuntu.com/usn/usn-652-1" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2007/1837" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34331" } ], "sourceIdentifier": "cve@mitre.org", "vendorComments": [ { "comment": "Not vulnerable. This issue did not affect the versions of lcms as shipped with Red Hat Enterprise Linux 5.", "lastModified": "2008-12-03T00:00:00", "organization": "Red Hat" } ], "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2008-12-03 17:30
Modified
2025-04-09 00:30
Severity ?
Summary
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
littlecms | lcms | * | |
littlecms | lcms | 1.07 | |
littlecms | lcms | 1.08 | |
littlecms | lcms | 1.09 | |
littlecms | lcms | 1.10 | |
littlecms | lcms | 1.11 | |
littlecms | lcms | 1.12 | |
littlecms | lcms | 1.13 | |
littlecms | lcms | 1.14 | |
littlecms | lcms | 1.15 | |
littlecms | little_cms_color_engine | * | |
littlecms | little_cms_color_engine | 1.07 | |
littlecms | little_cms_color_engine | 1.08 | |
littlecms | little_cms_color_engine | 1.09 | |
littlecms | little_cms_color_engine | 1.10 | |
littlecms | little_cms_color_engine | 1.11 | |
littlecms | little_cms_color_engine | 1.12 | |
littlecms | little_cms_color_engine | 1.13 | |
littlecms | little_cms_color_engine | 1.14 | |
littlecms | little_cms_color_engine | 1.15 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:littlecms:lcms:*:*:*:*:*:*:*:*", "matchCriteriaId": "3921D964-CEBA-4100-8AFA-37CE87C9D939", "versionEndIncluding": "1.16", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.07:*:*:*:*:*:*:*", "matchCriteriaId": "77D8173F-F341-4B34-A50A-388C93CABD01", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.08:*:*:*:*:*:*:*", "matchCriteriaId": "405F539C-0A33-4703-8ADA-AF314EC92B76", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.09:*:*:*:*:*:*:*", "matchCriteriaId": "7DCBA042-6C91-4CDD-96A6-5E99B60519C5", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.10:*:*:*:*:*:*:*", "matchCriteriaId": "C3F25567-8DEF-491C-97F7-D2680115C02E", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.11:*:*:*:*:*:*:*", "matchCriteriaId": "492B453F-5FC7-4B8B-9C42-C911FCA4BFDF", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.12:*:*:*:*:*:*:*", "matchCriteriaId": "CEFA9E7E-B7A9-4106-A480-0E57FCDA7B5F", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.13:*:*:*:*:*:*:*", "matchCriteriaId": "17B723CE-5A76-4DCE-9A2C-EFF32D4A5855", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.14:*:*:*:*:*:*:*", "matchCriteriaId": "39EBE224-D0B7-4C74-B363-1BDA291594D1", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.15:*:*:*:*:*:*:*", "matchCriteriaId": "14BBFB7C-206E-47F5-9F78-50DB88E09215", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:*", "matchCriteriaId": "76B826F6-61F2-47E2-A78D-7347904A34C2", "versionEndIncluding": "1.16", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.07:*:*:*:*:*:*:*", "matchCriteriaId": "F3E1F2A4-2D67-4442-991B-BDD66DFD0A36", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.08:*:*:*:*:*:*:*", "matchCriteriaId": "57F07310-A04B-49F3-B0F8-3B2BD1A70555", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.09:*:*:*:*:*:*:*", "matchCriteriaId": "F433BC9D-C6B2-446D-976C-7A4BB4F2F668", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.10:*:*:*:*:*:*:*", "matchCriteriaId": "7F153ED4-BC68-44F1-A8E6-284FDCD4D7CA", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.11:*:*:*:*:*:*:*", "matchCriteriaId": "7287F9F3-504E-4DB7-B189-B11DB0A9890C", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.12:*:*:*:*:*:*:*", "matchCriteriaId": "0D086B58-D972-461D-A7D3-F12CDFD3845E", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.13:*:*:*:*:*:*:*", "matchCriteriaId": "B0F21DB4-D8CA-48F0-9EFE-4F1D90108663", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.14:*:*:*:*:*:*:*", "matchCriteriaId": "041BE71F-DCDC-47A7-8FF5-1B9A97FDB324", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.15:*:*:*:*:*:*:*", "matchCriteriaId": "650BF28E-8D28-45C0-99C2-D6B78AA9BE6D", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain \"number of entries\" value, which is interpreted improperly, leading to an allocation of insufficient memory." }, { "lang": "es", "value": "Error de presencia de signo en entero en la funci\u00f3n cmsAllocGamma en src/cmsgamma.c en Little cms color engine (alias lcms) en versiones anteriores a 1.17 que permite a los atacantes tener un impacto desconocido a trav\u00e9s de un archivo que contiene un cierto n\u00famero de valores de entrada, que son interpretados inapropiadamente, permitiendo una asignaci\u00f3n de memoria insuficiente." } ], "id": "CVE-2008-5317", "lastModified": "2025-04-09T00:30:58.490", "metrics": { "cvssMetricV2": [ { "acInsufInfo": true, "baseSeverity": "HIGH", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 10.0, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ] }, "published": "2008-12-03T17:30:00.540", "references": [ { "source": "cve@mitre.org", "tags": [ "Patch" ], "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.c?view=diff\u0026r1=1.16\u0026r2=1.17" }, { "source": "cve@mitre.org", "url": "http://secunia.com/advisories/33066" }, { "source": "cve@mitre.org", "url": "http://secunia.com/advisories/33219" }, { "source": "cve@mitre.org", "url": "http://www.debian.org/security/2008/dsa-1684" }, { "source": "cve@mitre.org", "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "source": "cve@mitre.org", "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "source": "cve@mitre.org", "url": "http://www.securityfocus.com/bid/32708" }, { "source": "cve@mitre.org", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47120" }, { "source": "cve@mitre.org", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10685" }, { "source": "cve@mitre.org", "url": "https://usn.ubuntu.com/693-1/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch" ], "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.c?view=diff\u0026r1=1.16\u0026r2=1.17" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/33066" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/33219" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.debian.org/security/2008/dsa-1684" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/32708" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47120" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10685" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://usn.ubuntu.com/693-1/" } ], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-189" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2008-12-03 17:30
Modified
2025-04-09 00:30
Severity ?
Summary
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
littlecms | lcms | * | |
littlecms | lcms | 1.07 | |
littlecms | lcms | 1.08 | |
littlecms | lcms | 1.09 | |
littlecms | lcms | 1.10 | |
littlecms | lcms | 1.11 | |
littlecms | lcms | 1.12 | |
littlecms | lcms | 1.13 | |
littlecms | lcms | 1.14 | |
littlecms | little_cms_color_engine | * | |
littlecms | little_cms_color_engine | 1.07 | |
littlecms | little_cms_color_engine | 1.08 | |
littlecms | little_cms_color_engine | 1.09 | |
littlecms | little_cms_color_engine | 1.10 | |
littlecms | little_cms_color_engine | 1.11 | |
littlecms | little_cms_color_engine | 1.12 | |
littlecms | little_cms_color_engine | 1.13 | |
littlecms | little_cms_color_engine | 1.14 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:littlecms:lcms:*:*:*:*:*:*:*:*", "matchCriteriaId": "F88D4AAB-DA31-4CFA-AF12-478C33A559C2", "versionEndIncluding": "1.15", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.07:*:*:*:*:*:*:*", "matchCriteriaId": "77D8173F-F341-4B34-A50A-388C93CABD01", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.08:*:*:*:*:*:*:*", "matchCriteriaId": "405F539C-0A33-4703-8ADA-AF314EC92B76", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.09:*:*:*:*:*:*:*", "matchCriteriaId": "7DCBA042-6C91-4CDD-96A6-5E99B60519C5", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.10:*:*:*:*:*:*:*", "matchCriteriaId": "C3F25567-8DEF-491C-97F7-D2680115C02E", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.11:*:*:*:*:*:*:*", "matchCriteriaId": "492B453F-5FC7-4B8B-9C42-C911FCA4BFDF", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.12:*:*:*:*:*:*:*", "matchCriteriaId": "CEFA9E7E-B7A9-4106-A480-0E57FCDA7B5F", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.13:*:*:*:*:*:*:*", "matchCriteriaId": "17B723CE-5A76-4DCE-9A2C-EFF32D4A5855", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:lcms:1.14:*:*:*:*:*:*:*", "matchCriteriaId": "39EBE224-D0B7-4C74-B363-1BDA291594D1", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:*", "matchCriteriaId": "1A2834DF-6FA0-4305-85AD-179157C8FEF1", "versionEndIncluding": "1.15", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.07:*:*:*:*:*:*:*", "matchCriteriaId": "F3E1F2A4-2D67-4442-991B-BDD66DFD0A36", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.08:*:*:*:*:*:*:*", "matchCriteriaId": "57F07310-A04B-49F3-B0F8-3B2BD1A70555", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.09:*:*:*:*:*:*:*", "matchCriteriaId": "F433BC9D-C6B2-446D-976C-7A4BB4F2F668", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.10:*:*:*:*:*:*:*", "matchCriteriaId": "7F153ED4-BC68-44F1-A8E6-284FDCD4D7CA", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.11:*:*:*:*:*:*:*", "matchCriteriaId": "7287F9F3-504E-4DB7-B189-B11DB0A9890C", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.12:*:*:*:*:*:*:*", "matchCriteriaId": "0D086B58-D972-461D-A7D3-F12CDFD3845E", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.13:*:*:*:*:*:*:*", "matchCriteriaId": "B0F21DB4-D8CA-48F0-9EFE-4F1D90108663", "vulnerable": true }, { "criteria": "cpe:2.3:a:littlecms:little_cms_color_engine:1.14:*:*:*:*:*:*:*", "matchCriteriaId": "041BE71F-DCDC-47A7-8FF5-1B9A97FDB324", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of \"the input file,\" a different vulnerability than CVE-2007-2741." }, { "lang": "es", "value": "Desbordamiento de b\u00fafer en la funci\u00f3n ReadEmbeddedTextTag en src/cmsio1.c en el motor de color Little cms (alias lcms), versiones anteriores a 1.16 que permite a los atacantes remotos conseguir un desconocido impacto a trav\u00e9s de vectores relativos a una longitud de par\u00e1metros con inconsistentes contenido del archivo de entra, una diferente vulnerabilidad a CVE-2007-2741." } ], "id": "CVE-2008-5316", "lastModified": "2025-04-09T00:30:58.490", "metrics": { "cvssMetricV2": [ { "acInsufInfo": true, "baseSeverity": "HIGH", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 10.0, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ] }, "published": "2008-12-03T17:30:00.510", "references": [ { "source": "cve@mitre.org", "tags": [ "Exploit", "Patch" ], "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsio1.c?r1=1.33\u0026r2=1.34" }, { "source": "cve@mitre.org", "url": "http://secunia.com/advisories/33066" }, { "source": "cve@mitre.org", "url": "http://www.debian.org/security/2008/dsa-1684" }, { "source": "cve@mitre.org", "tags": [ "Exploit" ], "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "source": "cve@mitre.org", "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "source": "cve@mitre.org", "url": "http://www.securityfocus.com/bid/32708" }, { "source": "cve@mitre.org", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47119" }, { "source": "cve@mitre.org", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10531" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit", "Patch" ], "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsio1.c?r1=1.33\u0026r2=1.34" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/33066" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.debian.org/security/2008/dsa-1684" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit" ], "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/32708" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47119" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10531" } ], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
CVE-2007-2741 (GCVE-0-2007-2741)
Vulnerability from cvelistv5
Published
2007-05-17 19:00
Modified
2024-08-07 13:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.
References
► | URL | Tags | |||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-07T13:49:57.253Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "36179", "tags": [ "vdb-entry", "x_refsource_OSVDB", "x_transferred" ], "url": "http://osvdb.org/36179" }, { "name": "ADV-2007-1837", "tags": [ "vdb-entry", "x_refsource_VUPEN", "x_transferred" ], "url": "http://www.vupen.com/english/advisories/2007/1837" }, { "name": "32282", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/32282" }, { "name": "USN-652-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU", "x_transferred" ], "url": "http://www.ubuntu.com/usn/usn-652-1" }, { "name": "littlecms-iccprofile-bo(34331)", "tags": [ "vdb-entry", "x_refsource_XF", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34331" }, { "name": "27756", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/27756" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "http://scary.beasts.org/security/CESA-2007-001.html" }, { "name": "SUSE-SR:2007:024", "tags": [ "vendor-advisory", "x_refsource_SUSE", "x_transferred" ], "url": "http://www.novell.com/linux/security/advisories/2007_24_sr.html" }, { "name": "25294", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/25294" }, { "name": "MDKSA-2007:238", "tags": [ "vendor-advisory", "x_refsource_MANDRIVA", "x_transferred" ], "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:238" }, { "name": "24001", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/24001" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2007-05-15T00:00:00", "descriptions": [ { "lang": "en", "value": "Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-07-28T12:57:01", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre" }, "references": [ { "name": "36179", "tags": [ "vdb-entry", "x_refsource_OSVDB" ], "url": "http://osvdb.org/36179" }, { "name": "ADV-2007-1837", "tags": [ "vdb-entry", "x_refsource_VUPEN" ], "url": "http://www.vupen.com/english/advisories/2007/1837" }, { "name": "32282", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/32282" }, { "name": "USN-652-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU" ], "url": "http://www.ubuntu.com/usn/usn-652-1" }, { "name": "littlecms-iccprofile-bo(34331)", "tags": [ "vdb-entry", "x_refsource_XF" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34331" }, { "name": "27756", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/27756" }, { "tags": [ "x_refsource_MISC" ], "url": "http://scary.beasts.org/security/CESA-2007-001.html" }, { "name": "SUSE-SR:2007:024", "tags": [ "vendor-advisory", "x_refsource_SUSE" ], "url": "http://www.novell.com/linux/security/advisories/2007_24_sr.html" }, { "name": "25294", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/25294" }, { "name": "MDKSA-2007:238", "tags": [ "vendor-advisory", "x_refsource_MANDRIVA" ], "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:238" }, { "name": "24001", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/24001" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2007-2741", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "36179", "refsource": "OSVDB", "url": "http://osvdb.org/36179" }, { "name": "ADV-2007-1837", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2007/1837" }, { "name": "32282", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/32282" }, { "name": "USN-652-1", "refsource": "UBUNTU", "url": "http://www.ubuntu.com/usn/usn-652-1" }, { "name": "littlecms-iccprofile-bo(34331)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34331" }, { "name": "27756", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/27756" }, { "name": "http://scary.beasts.org/security/CESA-2007-001.html", "refsource": "MISC", "url": "http://scary.beasts.org/security/CESA-2007-001.html" }, { "name": "SUSE-SR:2007:024", "refsource": "SUSE", "url": "http://www.novell.com/linux/security/advisories/2007_24_sr.html" }, { "name": "25294", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/25294" }, { "name": "MDKSA-2007:238", "refsource": "MANDRIVA", "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:238" }, { "name": "24001", "refsource": "BID", "url": "http://www.securityfocus.com/bid/24001" } ] } } } }, "cveMetadata": { "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2007-2741", "datePublished": "2007-05-17T19:00:00", "dateReserved": "2007-05-17T00:00:00", "dateUpdated": "2024-08-07T13:49:57.253Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2009-0793 (GCVE-0-2009-0793)
Vulnerability from cvelistv5
Published
2009-04-09 15:00
Modified
2024-08-07 04:48
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
References
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-07T04:48:51.902Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "MDVSA-2009:137", "tags": [ "vendor-advisory", "x_refsource_MANDRIVA", "x_transferred" ], "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" }, { "name": "34635", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/34635" }, { "name": "34632", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/34632" }, { "name": "FEDORA-2009-3914", "tags": [ "vendor-advisory", "x_refsource_FEDORA", "x_transferred" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00233.html" }, { "name": "34623", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/34623" }, { "name": "USN-1043-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU", "x_transferred" ], "url": "http://www.ubuntu.com/usn/USN-1043-1" }, { "name": "34675", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/34675" }, { "name": "ADV-2009-0964", "tags": [ "vdb-entry", "x_refsource_VUPEN", "x_transferred" ], "url": "http://www.vupen.com/english/advisories/2009/0964" }, { "name": "35048", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/35048" }, { "name": "FEDORA-2009-3426", "tags": [ "vendor-advisory", "x_refsource_FEDORA", "x_transferred" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00204.html" }, { "name": "RHSA-2009:0377", "tags": [ "vendor-advisory", "x_refsource_REDHAT", "x_transferred" ], "url": "https://rhn.redhat.com/errata/RHSA-2009-0377.html" }, { "name": "34782", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/34782" }, { "name": "ADV-2011-0087", "tags": [ "vdb-entry", "x_refsource_VUPEN", "x_transferred" ], "url": "http://www.vupen.com/english/advisories/2011/0087" }, { "name": "oval:org.mitre.oval:def:11340", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL", "x_transferred" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11340" }, { "name": "MDVSA-2009:162", "tags": [ "vendor-advisory", "x_refsource_MANDRIVA", "x_transferred" ], "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" }, { "name": "FEDORA-2009-3425", "tags": [ "vendor-advisory", "x_refsource_FEDORA", "x_transferred" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00203.html" }, { "name": "34411", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/34411" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=492353" }, { "name": "34420", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/34420" }, { "name": "DSA-1769", "tags": [ "vendor-advisory", "x_refsource_DEBIAN", "x_transferred" ], "url": "http://www.debian.org/security/2009/dsa-1769" }, { "name": "ADV-2009-0963", "tags": [ "vdb-entry", "x_refsource_VUPEN", "x_transferred" ], "url": "http://www.vupen.com/english/advisories/2009/0963" }, { "name": "FEDORA-2009-3967", "tags": [ "vendor-advisory", "x_refsource_FEDORA", "x_transferred" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00285.html" }, { "name": "34634", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/34634" }, { "name": "MDVSA-2009:121", "tags": [ "vendor-advisory", "x_refsource_MANDRIVA", "x_transferred" ], "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:121" }, { "name": "42870", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/42870" }, { "name": "GLSA-200904-19", "tags": [ "vendor-advisory", "x_refsource_GENTOO", "x_transferred" ], "url": "http://security.gentoo.org/glsa/glsa-200904-19.xml" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2009-04-06T00:00:00", "descriptions": [ { "lang": "en", "value": "cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for \"transformations of monochrome profiles.\"" } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-09-28T12:57:01", "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat" }, "references": [ { "name": "MDVSA-2009:137", "tags": [ "vendor-advisory", "x_refsource_MANDRIVA" ], "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" }, { "name": "34635", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/34635" }, { "name": "34632", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/34632" }, { "name": "FEDORA-2009-3914", "tags": [ "vendor-advisory", "x_refsource_FEDORA" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00233.html" }, { "name": "34623", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/34623" }, { "name": "USN-1043-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU" ], "url": "http://www.ubuntu.com/usn/USN-1043-1" }, { "name": "34675", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/34675" }, { "name": "ADV-2009-0964", "tags": [ "vdb-entry", "x_refsource_VUPEN" ], "url": "http://www.vupen.com/english/advisories/2009/0964" }, { "name": "35048", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/35048" }, { "name": "FEDORA-2009-3426", "tags": [ "vendor-advisory", "x_refsource_FEDORA" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00204.html" }, { "name": "RHSA-2009:0377", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "https://rhn.redhat.com/errata/RHSA-2009-0377.html" }, { "name": "34782", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/34782" }, { "name": "ADV-2011-0087", "tags": [ "vdb-entry", "x_refsource_VUPEN" ], "url": "http://www.vupen.com/english/advisories/2011/0087" }, { "name": "oval:org.mitre.oval:def:11340", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11340" }, { "name": "MDVSA-2009:162", "tags": [ "vendor-advisory", "x_refsource_MANDRIVA" ], "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" }, { "name": "FEDORA-2009-3425", "tags": [ "vendor-advisory", "x_refsource_FEDORA" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00203.html" }, { "name": "34411", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/34411" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=492353" }, { "name": "34420", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/34420" }, { "name": "DSA-1769", "tags": [ "vendor-advisory", "x_refsource_DEBIAN" ], "url": "http://www.debian.org/security/2009/dsa-1769" }, { "name": "ADV-2009-0963", "tags": [ "vdb-entry", "x_refsource_VUPEN" ], "url": "http://www.vupen.com/english/advisories/2009/0963" }, { "name": "FEDORA-2009-3967", "tags": [ "vendor-advisory", "x_refsource_FEDORA" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00285.html" }, { "name": "34634", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/34634" }, { "name": "MDVSA-2009:121", "tags": [ "vendor-advisory", "x_refsource_MANDRIVA" ], "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:121" }, { "name": "42870", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/42870" }, { "name": "GLSA-200904-19", "tags": [ "vendor-advisory", "x_refsource_GENTOO" ], "url": "http://security.gentoo.org/glsa/glsa-200904-19.xml" } ] } }, "cveMetadata": { "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "assignerShortName": "redhat", "cveId": "CVE-2009-0793", "datePublished": "2009-04-09T15:00:00", "dateReserved": "2009-03-04T00:00:00", "dateUpdated": "2024-08-07T04:48:51.902Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2008-5317 (GCVE-0-2008-5317)
Vulnerability from cvelistv5
Published
2008-12-03 17:00
Modified
2024-08-07 10:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
References
► | URL | Tags | ||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-07T10:49:12.438Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "33219", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/33219" }, { "name": "32708", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/32708" }, { "name": "33066", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/33066" }, { "name": "oval:org.mitre.oval:def:10685", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL", "x_transferred" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10685" }, { "name": "DSA-1684", "tags": [ "vendor-advisory", "x_refsource_DEBIAN", "x_transferred" ], "url": "http://www.debian.org/security/2008/dsa-1684" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.c?view=diff\u0026r1=1.16\u0026r2=1.17" }, { "name": "[oss-security] 20081128 CVE request: lcms (old issues)", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "name": "lcms-cmsallocgamma-bo(47120)", "tags": [ "vdb-entry", "x_refsource_XF", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47120" }, { "name": "RHSA-2009:0011", "tags": [ "vendor-advisory", "x_refsource_REDHAT", "x_transferred" ], "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "name": "USN-693-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU", "x_transferred" ], "url": "https://usn.ubuntu.com/693-1/" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2008-11-28T00:00:00", "descriptions": [ { "lang": "en", "value": "Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain \"number of entries\" value, which is interpreted improperly, leading to an allocation of insufficient memory." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2018-10-03T20:57:01", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre" }, "references": [ { "name": "33219", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/33219" }, { "name": "32708", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/32708" }, { "name": "33066", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/33066" }, { "name": "oval:org.mitre.oval:def:10685", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10685" }, { "name": "DSA-1684", "tags": [ "vendor-advisory", "x_refsource_DEBIAN" ], "url": "http://www.debian.org/security/2008/dsa-1684" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.c?view=diff\u0026r1=1.16\u0026r2=1.17" }, { "name": "[oss-security] 20081128 CVE request: lcms (old issues)", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "name": "lcms-cmsallocgamma-bo(47120)", "tags": [ "vdb-entry", "x_refsource_XF" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47120" }, { "name": "RHSA-2009:0011", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "name": "USN-693-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU" ], "url": "https://usn.ubuntu.com/693-1/" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2008-5317", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain \"number of entries\" value, which is interpreted improperly, leading to an allocation of insufficient memory." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "33219", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/33219" }, { "name": "32708", "refsource": "BID", "url": "http://www.securityfocus.com/bid/32708" }, { "name": "33066", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/33066" }, { "name": "oval:org.mitre.oval:def:10685", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10685" }, { "name": "DSA-1684", "refsource": "DEBIAN", "url": "http://www.debian.org/security/2008/dsa-1684" }, { "name": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.c?view=diff\u0026r1=1.16\u0026r2=1.17", "refsource": "CONFIRM", "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.c?view=diff\u0026r1=1.16\u0026r2=1.17" }, { "name": "[oss-security] 20081128 CVE request: lcms (old issues)", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "name": "lcms-cmsallocgamma-bo(47120)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47120" }, { "name": "RHSA-2009:0011", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "name": "USN-693-1", "refsource": "UBUNTU", "url": "https://usn.ubuntu.com/693-1/" } ] } } } }, "cveMetadata": { "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2008-5317", "datePublished": "2008-12-03T17:00:00", "dateReserved": "2008-12-03T00:00:00", "dateUpdated": "2024-08-07T10:49:12.438Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2008-5316 (GCVE-0-2008-5316)
Vulnerability from cvelistv5
Published
2008-12-03 17:00
Modified
2024-08-07 10:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.
References
► | URL | Tags | ||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-07T10:49:12.171Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsio1.c?r1=1.33\u0026r2=1.34" }, { "name": "32708", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/32708" }, { "name": "33066", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/33066" }, { "name": "DSA-1684", "tags": [ "vendor-advisory", "x_refsource_DEBIAN", "x_transferred" ], "url": "http://www.debian.org/security/2008/dsa-1684" }, { "name": "oval:org.mitre.oval:def:10531", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL", "x_transferred" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10531" }, { "name": "[oss-security] 20081128 CVE request: lcms (old issues)", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "name": "RHSA-2009:0011", "tags": [ "vendor-advisory", "x_refsource_REDHAT", "x_transferred" ], "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "name": "lcms-readembeddedtexttag-bo(47119)", "tags": [ "vdb-entry", "x_refsource_XF", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47119" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2008-11-28T00:00:00", "descriptions": [ { "lang": "en", "value": "Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of \"the input file,\" a different vulnerability than CVE-2007-2741." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-09-28T12:57:01", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsio1.c?r1=1.33\u0026r2=1.34" }, { "name": "32708", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/32708" }, { "name": "33066", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/33066" }, { "name": "DSA-1684", "tags": [ "vendor-advisory", "x_refsource_DEBIAN" ], "url": "http://www.debian.org/security/2008/dsa-1684" }, { "name": "oval:org.mitre.oval:def:10531", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10531" }, { "name": "[oss-security] 20081128 CVE request: lcms (old issues)", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "name": "RHSA-2009:0011", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "name": "lcms-readembeddedtexttag-bo(47119)", "tags": [ "vdb-entry", "x_refsource_XF" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47119" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2008-5316", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of \"the input file,\" a different vulnerability than CVE-2007-2741." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsio1.c?r1=1.33\u0026r2=1.34", "refsource": "CONFIRM", "url": "http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsio1.c?r1=1.33\u0026r2=1.34" }, { "name": "32708", "refsource": "BID", "url": "http://www.securityfocus.com/bid/32708" }, { "name": "33066", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/33066" }, { "name": "DSA-1684", "refsource": "DEBIAN", "url": "http://www.debian.org/security/2008/dsa-1684" }, { "name": "oval:org.mitre.oval:def:10531", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10531" }, { "name": "[oss-security] 20081128 CVE request: lcms (old issues)", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2008/11/28/3" }, { "name": "RHSA-2009:0011", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2009-0011.html" }, { "name": "lcms-readembeddedtexttag-bo(47119)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47119" } ] } } } }, "cveMetadata": { "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2008-5316", "datePublished": "2008-12-03T17:00:00", "dateReserved": "2008-12-03T00:00:00", "dateUpdated": "2024-08-07T10:49:12.171Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }