Vulnerabilities > Littlecms > Little CMS Color Engine > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-05-07 CVE-2013-7455 Unspecified vulnerability in Littlecms Little CMS Color Engine
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
network
low complexity
littlecms
critical
9.8