Unrated severityNVD Advisory· Published May 17, 2007· Updated Apr 23, 2026
CVE-2007-2741
CVE-2007-2741
Description
Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.
Affected products
8cpe:2.3:a:littlecms:lcms:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:littlecms:lcms:*:*:*:*:*:*:*:*range: <=1.14
- cpe:2.3:a:littlecms:lcms:1.07:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.08:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.09:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.10:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.11:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.12:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.13:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/25294nvdPatchVendor Advisory
- scary.beasts.org/security/CESA-2007-001.htmlnvdExploit
- www.securityfocus.com/bid/24001nvdExploitPatch
- secunia.com/advisories/27756nvdVendor Advisory
- secunia.com/advisories/32282nvdVendor Advisory
- www.vupen.com/english/advisories/2007/1837nvdVendor Advisory
- osvdb.org/36179nvd
- www.mandriva.com/security/advisoriesnvd
- www.novell.com/linux/security/advisories/2007_24_sr.htmlnvd
- www.ubuntu.com/usn/usn-652-1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/34331nvd
News mentions
0No linked articles in our index yet.