Lucene search

K
nvd[email protected]NVD:CVE-2013-4160
HistoryJan 21, 2014 - 6:55 p.m.

CVE-2013-4160

2014-01-2118:55:09
web.nvd.nist.gov

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.4

Confidence

Low

EPSS

0.024

Percentile

89.8%

Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.

Affected configurations

NVD
Node
littlecmslittle_cms_color_engineRange2.4
OR
littlecmslittle_cms_color_engineMatch1.07
OR
littlecmslittle_cms_color_engineMatch1.08
OR
littlecmslittle_cms_color_engineMatch1.09
OR
littlecmslittle_cms_color_engineMatch1.10
OR
littlecmslittle_cms_color_engineMatch1.11
OR
littlecmslittle_cms_color_engineMatch1.12
OR
littlecmslittle_cms_color_engineMatch1.13
OR
littlecmslittle_cms_color_engineMatch1.14
OR
littlecmslittle_cms_color_engineMatch1.15
OR
littlecmslittle_cms_color_engineMatch1.16
OR
littlecmslittle_cms_color_engineMatch1.17
OR
littlecmslittle_cms_color_engineMatch1.18
OR
littlecmslittle_cms_color_engineMatch1.19
OR
littlecmslittle_cms_color_engineMatch2.0
OR
littlecmslittle_cms_color_engineMatch2.1
OR
littlecmslittle_cms_color_engineMatch2.2
OR
littlecmslittle_cms_color_engineMatch2.3

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.4

Confidence

Low

EPSS

0.024

Percentile

89.8%