CVE-2013-7455: Littlecms Little CMS Color Engine
Critical severity, CVSS 9.8. EPSS: 6.2% chance of exploitation in the next 30 days.
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
Affected products
- Littlecms Little CMS Color Engine: version 2.0 only; version 2.1 only; version 2.2 only; version 2.3 only; version 2.4 only; version 2.5 only
Published 2016-05-07. Last modified 2026-06-17.