CVE-2016-10165 is an out-of-bounds heap read vulnerability in the Little CMS (lcms2) library, specifically within the Type_MLU_Read function in cmstypes.c. This flaw can be triggered by processing an image with a specially crafted ICC profile, potentially leading to sensitive information disclosure or a denial of service. The vulnerability affects various products including canonical, debian, littlecms, netapp, opensuse, and redhat. Rated with a CVSS score of 7.1 (HIGH), this vulnerability requires user interaction (UI:R) and local access (AV:L), but has low attack complexity (AC:L). The primary impacts are high confidentiality (C:H) and high availability (A:H) concerns. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11CPE matchmatch criteria | cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.