Littlecms is a modestly represented color-processing library embedded across imaging, document, and graphics applications where a single vulnerability can propagate widely through downstream consumers. Its vulnerability profile centers on the core color engine product and recurs through memory-safety weakness classes—out-of-bounds writes, buffer-boundary violations, and integer overflows—that reflect the low-level data manipulation inherent to color transformation routines. A meaningful share of disclosures reach serious severity; defenders should inventory products bundling this library and treat color-pipeline flaws as a supply-chain concern rather than isolated application issues. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Littlecms over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7455CRITICAL Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed | May 7, 2016 | 9.8 | 33 | NO | NO |
CVE-2026-41254HIGH Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. | Apr 18, 2026 | 7.5 | 30 | NO | NO |
CVE-2009-0733HIGH Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow cont | Mar 23, 2009 | 9.3 | 28 | NO | NO |
CVE-2009-0723HIGH Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrar | Mar 23, 2009 | 9.3 | 28 | NO | NO |
CVE-2008-5316HIGH Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related | Dec 3, 2008 | 10.0 | 28 | NO | NO |
CVE-2007-2741HIGH Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC pr | May 17, 2007 | 9.3 | 28 | NO | NO |
CVE-2008-5628MEDIUM SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands via the term parameter. | Dec 17, 2008 | 6.8 | 26 | NO | YES |
CVE-2016-10165HIGH The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted | Feb 3, 2017 | 7.1 | 25 | NO | NO |
CVE-2008-5317HIGH Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file con | Dec 3, 2008 | 10.0 | 25 | NO | NO |
CVE-2018-11556HIGH tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers | May 30, 2018 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Littlecms.
Media articles that mention a CVE ID that affects a product developed by Littlecms — matched by CVE ID, not by vendor name.