Double Free Vulnerability in Little CMS by Martin Odersky
CVE-2013-7455
9.8CRITICAL
What is CVE-2013-7455?
The Double Free vulnerability in the DefaultICCintents function of liblcms2 affects versions before 2.6. This flaw can be exploited by attackers through specially crafted ICC profiles, which may lead to arbitrary code execution due to mishandling of memory. The vulnerability arises in the error handling processes of this library, enabling potential disruptions and unauthorized actions in affected systems.
References
EPSS Score
15% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
