{"id":"CVE-2013-7455","details":"Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.","modified":"2026-04-10T03:43:28.734264Z","published":"2016-05-07T10:59:00Z","references":[{"type":"ADVISORY","url":"http://www.kb.cert.org/vuls/id/369800"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2961-1"},{"type":"FIX","url":"https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1db"},{"type":"WEB","url":"http://www.kb.cert.org/vuls/id/369800"},{"type":"WEB","url":"https://penteston.com/OSVDB-105462"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}