VYPR

ColorSync

by Apple Inc.

CVEs (4)

  • CVE-2021-30917HigAug 24, 2021
    risk 0.51cvss 7.8epss 0.02

    A memory corruption issue existed in the processing of ICC profiles. This issue was addressed with improved input validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007…

  • CVE-2009-1726Aug 6, 2009
    risk 0.01cvss epss 0.08

    Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.

  • CVE-2008-3642Oct 10, 2008
    risk 0.00cvss epss 0.06

    Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.

  • CVE-2007-4710Dec 19, 2007
    risk 0.00cvss epss 0.04

    Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via an image with a crafted ColorSync profile, which triggers memory corruption.