CVE-2026-34556
- EPSS 0.02%
- Veröffentlicht 31.03.2026 22:22:47
- Zuletzt bearbeitet 20.04.2026 14:39:50
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a heap-buffer-overflow (HBO) in icAnsiToUtf8() in the XML conversion path. The issue is triggered by a crafted ICC profile...
CVE-2026-34555
- EPSS 0.03%
- Veröffentlicht 31.03.2026 22:21:42
- Zuletzt bearbeitet 20.04.2026 14:38:31
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a stack-buffer-overflow (SBO) in CIccTagFixedNum<>::GetValues() and a related bug chain. The primary crash is an AddressSa...
CVE-2026-34554
- EPSS 0.02%
- Veröffentlicht 31.03.2026 22:19:26
- Zuletzt bearbeitet 20.04.2026 14:37:03
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a heap-buffer-overflow (HBO) in CIccApplyCmmSearch::costFunc() can be triggered via malformed JSON configuration input to the iccAp...
- EPSS 0.02%
- Veröffentlicht 31.03.2026 22:17:30
- Zuletzt bearbeitet 20.04.2026 14:36:32
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a defect in LUT dump/iteration logic affecting CIccCLUT::Iterate() and output produced by CIccMBB::Describe() (via CLUT du...
CVE-2026-34552
- EPSS 0.02%
- Veröffentlicht 31.03.2026 22:15:30
- Zuletzt bearbeitet 20.04.2026 14:34:19
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) issue in IccTagLut.cpp where the code performs member access through a null pointer of type CIc...
CVE-2026-34551
- EPSS 0.02%
- Veröffentlicht 31.03.2026 22:14:03
- Zuletzt bearbeitet 20.04.2026 14:33:37
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a null-pointer dereference (NPD) in CIccTagLut16::Write() can be triggered when processing a crafted ICC profile (embedded in a TIF...
CVE-2026-34550
- EPSS 0.02%
- Veröffentlicht 31.03.2026 22:12:29
- Zuletzt bearbeitet 20.04.2026 14:33:21
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccProfLib/IccIO.cpp caused by an implicit conversion from a negative signed integ...
CVE-2026-34549
- EPSS 0.02%
- Veröffentlicht 31.03.2026 22:11:21
- Zuletzt bearbeitet 20.04.2026 14:33:08
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccUtil.cpp triggered by a crafted input profile. Under UndefinedBehaviorSanitizer...
CVE-2026-34548
- EPSS 0.02%
- Veröffentlicht 31.03.2026 22:09:49
- Zuletzt bearbeitet 20.04.2026 14:32:53
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in the XML conversion tooling path (iccToXml) caused by an implicit conversion from a...
CVE-2026-34547
- EPSS 0.02%
- Veröffentlicht 31.03.2026 22:08:11
- Zuletzt bearbeitet 20.04.2026 14:31:56
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, an Undefined Behavior (UB) condition in IccUtil.cpp can be triggered by a crafted ICC profile when running iccDumpProfile. This iss...