VDB

GCVE-110-NCSC-2026-261

GCVE-110-NCSC-2026-261
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published July 22, 2026
Little CMS versions up to 2.18 contain integer overflow vulnerabilities in the CubeSize and ParseCube functions, as well as improper handling of malformed ICC profiles, leading to potential information disclosure, denial of service, or arbitrary code execution.

Weaknesses (CWE)

CWE-696Incorrect Behavior OrderCWE-295Improper Certificate ValidationCWE-787Out-of-bounds WriteCWE-1333Inefficient Regular Expression ComplexityCWE-190Integer Overflow or WraparoundCWE-476NULL Pointer DereferenceCWE-347Improper Verification of Cryptographic Signature

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
Oraclevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›