Loading...
Loading...
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.
January 21, 2014
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-4160
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.