Total vulnerabilities in the database
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.
Software | From | Fixed in |
---|---|---|
mozilla / firefox | 3.1-beta1 | 3.1-beta1.x |
gimp / gimp | - | - |
sun / openjdk | - | 7.x |
littlecms / little_cms | - | 1.17.x |