Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0723

Опубликовано: 23 мар. 2009
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*
Версия до 2.9.2 (исключая)
cpe:2.3:a:mozilla:firefox:3.1:beta1:*:*:*:*:*:*
cpe:2.3:a:sun:openjdk:*:*:*:*:*:*:*:*
Версия до 7 (включая)
Конфигурация 2
cpe:2.3:a:littlecms:little_cms:*:*:*:*:*:*:*:*
Версия до 1.17 (включая)

EPSS

Процентиль: 75%
0.00945
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-190

Связанные уязвимости

ubuntu
около 16 лет назад

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

redhat
больше 16 лет назад

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

debian
около 16 лет назад

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1 ...

github
около 3 лет назад

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

oracle-oval
больше 16 лет назад

ELSA-2009-0339: lcms security update (MODERATE)

EPSS

Процентиль: 75%
0.00945
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-190