VDB
GCVE-110-NCSC-2026-261
GCVE-110-NCSC-2026-261
Advisory PublishedCVSS 7.5/10
Little CMS versions up to 2.18 contain integer overflow vulnerabilities in the CubeSize and ParseCube functions, as well as improper handling of malformed ICC profiles, leading to potential information disclosure, denial of service, or arbitrary code execution.
Weaknesses (CWE)
CWE-696Incorrect Behavior OrderCWE-295Improper Certificate ValidationCWE-787Out-of-bounds WriteCWE-1333Inefficient Regular Expression ComplexityCWE-190Integer Overflow or WraparoundCWE-476NULL Pointer DereferenceCWE-347Improper Verification of Cryptographic Signature
Risk Scores
CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Oracle | vers:unknown/* | — | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.