Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0723

Опубликовано: 23 мар. 2009
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*
Версия до 2.9.2 (исключая)
cpe:2.3:a:mozilla:firefox:3.1:beta1:*:*:*:*:*:*
cpe:2.3:a:sun:openjdk:*:*:*:*:*:*:*:*
Версия до 7 (включая)
Конфигурация 2
cpe:2.3:a:littlecms:little_cms:*:*:*:*:*:*:*:*
Версия до 1.17 (включая)

EPSS

Процентиль: 75%
0.00858
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-190

Связанные уязвимости

ubuntu
почти 17 лет назад

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

redhat
почти 17 лет назад

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

debian
почти 17 лет назад

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1 ...

github
почти 4 года назад

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

oracle-oval
почти 17 лет назад

ELSA-2009-0339: lcms security update (MODERATE)

EPSS

Процентиль: 75%
0.00858
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-190