← Vulnerability feed

Vulnerability record · CVE-2009-0793 · published 9 April 2009

CVE-2009-0793: Littlecms lcms improper input validation vulnerability

Littlecms · Lcms

cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."

4.3 CVSS 2.0 Medium EPSS 4.8% · top 8.3% CWE-20 · Improper input validation
4.3CVSS 2.0 base score
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
52References
16 Jun 2026Last modified by NVD

Description

cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/34623
http://secunia.com/advisories/34632
http://secunia.com/advisories/34634 Vendor Advisory
http://secunia.com/advisories/34635 Vendor Advisory
http://secunia.com/advisories/34675
http://secunia.com/advisories/34782
http://secunia.com/advisories/35048
http://secunia.com/advisories/42870
http://security.gentoo.org/glsa/glsa-200904-19.xml
http://www.debian.org/security/2009/dsa-1769
http://www.mandriva.com/security/advisories?name=MDVSA-2009:121
http://www.mandriva.com/security/advisories?name=MDVSA-2009:137
http://www.mandriva.com/security/advisories?name=MDVSA-2009:162
http://www.securityfocus.com/bid/34411
http://www.securityfocus.com/bid/34420
http://www.ubuntu.com/usn/USN-1043-1
http://www.vupen.com/english/advisories/2009/0963 Vendor Advisory
http://www.vupen.com/english/advisories/2009/0964 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0087
https://bugzilla.redhat.com/show_bug.cgi?id=492353
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11340
https://rhn.redhat.com/errata/RHSA-2009-0377.html
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00203.html
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00204.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00233.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00285.html
http://secunia.com/advisories/34623
http://secunia.com/advisories/34632
http://secunia.com/advisories/34634 Vendor Advisory
http://secunia.com/advisories/34635 Vendor Advisory
http://secunia.com/advisories/34675
http://secunia.com/advisories/34782
http://secunia.com/advisories/35048
http://secunia.com/advisories/42870
http://security.gentoo.org/glsa/glsa-200904-19.xml
http://www.debian.org/security/2009/dsa-1769
http://www.mandriva.com/security/advisories?name=MDVSA-2009:121
http://www.mandriva.com/security/advisories?name=MDVSA-2009:137
http://www.mandriva.com/security/advisories?name=MDVSA-2009:162
http://www.securityfocus.com/bid/34411

Track CVE-2009-0793 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1896Sun openjdk permissions and access controls vulnerabilityThe Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an en…EPSS 3.0%10.0CVE-2009-2476Sun java se permissions and access controls vulnerabilityThe Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which …EPSS 2.9%10.0CVE-2009-2689Sun java se permissions and access controls vulnerabilityJDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecifie…EPSS 2.8%10.0CVE-2008-5316Littlecms lcms memory buffer overflow vulnerabilityBuffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unk…EPSS 2.8%10.0CVE-2008-5317Littlecms lcms vulnerabilityInteger signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have a…EPSS 2.2%9.3CVE-2009-0723Gimp integer overflow vulnerabilityMultiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependen…EPSS 5.0%9.3CVE-2009-0733Gimp out-of-bounds write vulnerabilityMultiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta…EPSS 5.5%9.3CVE-2007-2741Littlecms lcms memory buffer overflow vulnerabilityStack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (applicat…EPSS 7.9%

Source: NIST National Vulnerability Database (record CVE-2009-0793), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.