Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Littlecms

First CVE: May 17, 2007Active for: 19 yearsTotal CVEs: 17
34.1
VTI Score
Medium

Littlecms is a modestly represented color-processing library embedded across imaging, document, and graphics applications where a single vulnerability can propagate widely through downstream consumers. Its vulnerability profile centers on the core color engine product and recurs through memory-safety weakness classes—out-of-bounds writes, buffer-boundary violations, and integer overflows—that reflect the low-level data manipulation inherent to color transformation routines. A meaningful share of disclosures reach serious severity; defenders should inventory products bundling this library and treat color-pipeline flaws as a supply-chain concern rather than isolated application issues. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Littlecms over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 17, 2007
19 years ago
Most Recent CVE
Apr 30, 2026
85 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-7455CRITICAL
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed
May 7, 20169.833NONO
CVE-2026-41254HIGH
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Apr 18, 20267.530NONO
CVE-2009-0733HIGH
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow cont
Mar 23, 20099.328NONO
CVE-2009-0723HIGH
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrar
Mar 23, 20099.328NONO
CVE-2008-5316HIGH
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related
Dec 3, 200810.028NONO
CVE-2007-2741HIGH
Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC pr
May 17, 20079.328NONO
CVE-2008-5628MEDIUM
SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands via the term parameter.
Dec 17, 20086.826NOYES
CVE-2016-10165HIGH
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted
Feb 3, 20177.125NONO
CVE-2008-5317HIGH
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file con
Dec 3, 200810.025NONO
CVE-2018-11556HIGH
tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers
May 30, 20187.824NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
41%
53%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (29.4%)
Network2 (11.8%)
Unknown10 (58.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (35.3%)
High1 (5.9%)
Unknown10 (58.8%)
User Interaction
None3 (17.6%)
Unknown10 (58.8%)
Required4 (23.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (41.2%)
Unknown10 (58.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Littlecms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Littlecms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Littlecms's Products

View all 3 CNAs →

Top CWEs