Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24405

Опубликовано: 24 янв. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buffer Overflow vulnerability in CIccMpeCalculator::Read(). This occurs when user-controllable input is unsafely incorporated into ICC profile data or other structured binary blobs. Successful exploitation may allow an attacker to perform DoS, manipulate data, bypass application logic and Code Execution. This issue has been fixed in version 2.3.1.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*
Версия до 2.3.1.2 (исключая)

EPSS

Процентиль: 30%
0.00113
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

EPSS

Процентиль: 30%
0.00113
Низкий

8.8 High

CVSS3

Дефекты

CWE-20