VDB
CVE-2009-0733
CVE-2009-0733
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.
EPSS 5.53% · 92.5th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
5.53%
92.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sun | openjdk | 0 |
| littlecms | little_cms | 0 |
| gimp | gimp | 0 |
| n/a | n/a | n/a |
| mozilla | firefox | 3.1 |
Timeline
- Mar 23, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
References
- FEDORA-2009-2970 vendor-advisory
- MDVSA-2009:137 vendor-advisory
- 34632 third-party-advisory
- 1021869 vdb
- FEDORA-2009-2928 vendor-advisory
- USN-744-1 vendor-advisory
- 34454 third-party-advisory
- FEDORA-2009-2982 vendor-advisory
- FEDORA-2009-3034 vendor-advisory
- FEDORA-2009-2903 vendor-advisory
- http://scary.beasts.org/security/CESA-2009-003.html url
- 34382 third-party-advisory
- SSA:2009-083-01 vendor-advisory
- 34418 third-party-advisory
- 20090320 [oCERT-2009-003] LittleCMS integer errors mailing-list
- RHSA-2009:0377 vendor-advisory
- 34782 third-party-advisory
- MDVSA-2009:162 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=487512 url
- 34463 third-party-advisory
…and 22 more