CVE-2026-30984
- EPSS 0.01%
- Veröffentlicht 10.03.2026 17:53:49
- Zuletzt bearbeitet 13.03.2026 20:29:03
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap out-of-bounds read in CIccCalculatorFunc::ApplySequence() causing an application crash. This vulnerability is fixed in 2.3....
CVE-2026-30983
- EPSS 0.01%
- Veröffentlicht 10.03.2026 17:52:28
- Zuletzt bearbeitet 13.03.2026 20:28:51
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack buffer overflow in icFixXml() (strcpy) causing stack memory corruption or crash. This vulnerability is fixed in 2.3.1.5.
CVE-2026-30982
- EPSS 0.01%
- Veröffentlicht 10.03.2026 17:50:59
- Zuletzt bearbeitet 13.03.2026 20:28:43
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap out-of-bounds read in CIccPcsXform::pushXYZConvert() causing crash and potentially leaking memory contents. This vulnerabil...
CVE-2026-30981
- EPSS 0.01%
- Veröffentlicht 10.03.2026 17:49:31
- Zuletzt bearbeitet 13.03.2026 20:28:34
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-buffer-overflow read in CIccXmlArrayType<>::DumpArray() causing out-of-bounds read and/or crash. This vulnerability is fixe...
CVE-2026-30979
- EPSS 0.01%
- Veröffentlicht 10.03.2026 17:47:57
- Zuletzt bearbeitet 13.03.2026 20:28:03
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp() triggered with local user interaction causing memory corruption...
CVE-2026-30978
- EPSS 0.02%
- Veröffentlicht 10.03.2026 17:46:18
- Zuletzt bearbeitet 13.03.2026 20:27:31
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-use-after-free in CIccCmm::AddXform() causing invalid vptr dereference and crash. This vulnerability is fixed in 2.3.1.5.
CVE-2026-27692
- EPSS 0.01%
- Veröffentlicht 25.02.2026 14:40:22
- Zuletzt bearbeitet 26.02.2026 15:43:56
iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer whi...
CVE-2026-27691
- EPSS 0.01%
- Veröffentlicht 25.02.2026 14:36:16
- Zuletzt bearbeitet 26.02.2026 15:50:36
iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, signed integer overflow in iccFromCube.cpp during multiplication triggers undefined behavior, potentially causing cr...
CVE-2026-25634
- EPSS 0.02%
- Veröffentlicht 06.02.2026 20:21:40
- Zuletzt bearbeitet 19.02.2026 17:55:29
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to 2.3.1.4, SrcPixel and DestPixel stack buffers overlap in CIccTagMultiProcessElement::Apply() int Icc...
CVE-2026-25584
- EPSS 0.01%
- Veröffentlicht 04.02.2026 22:16:01
- Zuletzt bearbeitet 18.02.2026 18:37:23
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a stack-buffer-overflow vulnerability in CIccTagFloatNum<>::GetValues(). T...