← Vulnerability feed

Vulnerability record · CVE-2008-5316 · published 3 December 2008

CVE-2008-5316: Littlecms lcms memory buffer overflow vulnerability

Littlecms · Lcms

Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.

10.0 CVSS 2.0 High EPSS 2.8% · top 14.2% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5316 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-5317Littlecms lcms vulnerabilityInteger signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have a…EPSS 2.2%9.8CVE-2013-7455Littlecms little cms color engine vulnerabilityDouble free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute…EPSS 6.2%9.3CVE-2007-2741Littlecms lcms memory buffer overflow vulnerabilityStack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (applicat…EPSS 7.9%7.1CVE-2016-10165Littlecms little cms color engine out-of-bounds read vulnerabilityThe Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of servi…EPSS 2.8%5.5CVE-2018-16435Littlecms little cms color engine integer overflow vulnerabilityLittle CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based bu…EPSS 1.7%5.0CVE-2013-4160Littlecms little cms color engine vulnerabilityLittle CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer d…EPSS 2.8%4.3CVE-2013-4276Littlecms little cms color engine memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash)…EPSS 3.5%4.3CVE-2009-0793Littlecms lcms improper input validation vulnerabilitycmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL…EPSS 4.8%

Source: NIST National Vulnerability Database (record CVE-2008-5316), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.