Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.16
                        
                    
                    
                        
                            EPSS Ranking 94.5%