littlecms CVE Vulnerabilities & Metrics

Focus on littlecms vulnerabilities and metrics.

Last updated: 16 Jun 2026, 22:25 UTC

About littlecms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with littlecms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total littlecms CVEs: 6
Earliest CVE date: 17 May 2007, 19:30 UTC
Latest CVE date: 18 Apr 2026, 07:16 UTC

Latest CVE reference: CVE-2026-41254

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical littlecms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.63

Max CVSS: 10.0

Critical CVEs (≥9): 6

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 8
7.0-8.9 0
9.0-10.0 6

CVSS Distribution Chart

Top 5 Highest CVSS littlecms CVEs

These are the five CVEs with the highest CVSS scores for littlecms, sorted by severity first and recency.

All CVEs for littlecms

CVE-2026-41254 littlecms vulnerability CVSS: 0 18 Apr 2026, 07:16 UTC

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

CVE-2018-16435 littlecms vulnerability CVSS: 4.3 04 Sep 2018, 00:29 UTC

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVE-2018-11556 littlecms vulnerability CVSS: 6.8 30 May 2018, 04:29 UTC

tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”

CVE-2018-11555 littlecms vulnerability CVSS: 6.8 30 May 2018, 04:29 UTC

tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”

CVE-2016-10165 littlecms vulnerability CVSS: 5.8 03 Feb 2017, 19:59 UTC

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

CVE-2013-7455 littlecms vulnerability CVSS: 10.0 07 May 2016, 10:59 UTC

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

CVE-2013-4160 littlecms vulnerability CVSS: 5.0 21 Jan 2014, 18:55 UTC

Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.

CVE-2013-4276 littlecms vulnerability CVSS: 4.3 28 Sep 2013, 19:55 UTC

Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility.

CVE-2009-0793 littlecms vulnerability CVSS: 4.3 09 Apr 2009, 15:08 UTC

cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."

CVE-2009-0733 littlecms vulnerability CVSS: 9.3 23 Mar 2009, 14:19 UTC

Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.

CVE-2009-0723 littlecms vulnerability CVSS: 9.3 23 Mar 2009, 14:19 UTC

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

CVE-2009-0581 littlecms vulnerability CVSS: 4.3 23 Mar 2009, 14:19 UTC

Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.

CVE-2008-5317 littlecms vulnerability CVSS: 10.0 03 Dec 2008, 17:30 UTC

Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.

CVE-2008-5316 littlecms vulnerability CVSS: 10.0 03 Dec 2008, 17:30 UTC

Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.

CVE-2007-2741 littlecms vulnerability CVSS: 9.3 17 May 2007, 19:30 UTC

Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.