6.2

CVSS3.1

CVE-2026-34548 - iccDEV: UB at IccUtilXml.cpp

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in the XML conversion tooling path (iccToXml) caused by an implicit conversion from a negative signed integer to icUInt32Number (unsig…

πŸ“… Published: March 31, 2026, 10:09 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.2

CVSS3.1

CVE-2026-34547 - iccDEV: UB at IccUtil.cpp

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, an Undefined Behavior (UB) condition in IccUtil.cpp can be triggered by a crafted ICC profile when running iccDumpProfile. This issue has been patched in version 2.3.1.6.

πŸ“… Published: March 31, 2026, 10:08 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.2

CVSS3.1

CVE-2026-34546 - iccDEV: UB at TiffImg.h

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted TIFF input can trigger Undefined Behavior (UB) due to division by zero in the TIFF handling code paths used by iccTiffDump. This issue has been patched in version 2.3.1.6.

πŸ“… Published: March 31, 2026, 10:06 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.2

CVSS3.1

CVE-2026-34542 - iccDEV: SBO in CIccCalculatorFunc::Apply()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a stack-buffer-overflow (SBO) in CIccCalculatorFunc::Apply() when processed via iccApplyNamedCmm. Under AddressSanitizer, the failure is reported …

πŸ“… Published: March 31, 2026, 10:05 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.2

CVSS3.1

CVE-2026-34541 - iccDEV: UB in CIccCombinedConnectionConditions::CIccCombinedConnectionConditions()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger Undefined Behavior (UB) via a null-pointer member call in CIccCombinedConnectionConditions::CIccCombinedConnectionConditions() (reported by UBSan …

πŸ“… Published: March 31, 2026, 10:04 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.2

CVSS3.1

CVE-2026-34540 - iccDEV: HBO in icMemDump()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a heap-buffer-overflow (HBO) in icMemDump() when iccDumpProfile attempts to dump/describe malformed tag contents. The issue is observable under Ad…

πŸ“… Published: March 31, 2026, 10:03 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.2

CVSS3.1

CVE-2026-34539 - iccDEV: HBO in CTiffImg::WriteLine()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile and TIFF input can trigger a heap-buffer-overflow (HBO) in CTiffImg::WriteLine(). The issue is observable under AddressSanitizer as an out-of-bounds heap read…

πŸ“… Published: March 31, 2026, 10:01 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.2

CVSS3.1

CVE-2026-34537 - iccDEV: UB in CIccOpDefEnvVar::Exec()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger Undefined Behavior (UB) in CIccOpDefEnvVar::Exec() due to invalid enum values being loaded for icSigCmmEnvVar. The issue is observable under UBSan…

πŸ“… Published: March 31, 2026, 10 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.2

CVSS3.1

CVE-2026-34536 - iccDEV: SO in SIccCalcOp::ArgsUsed()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a stack overflow (SO) in SIccCalcOp::ArgsUsed(). The issue is observable under AddressSanitizer as a stack-overflow when iccApplyProfiles processe…

πŸ“… Published: March 31, 2026, 9:59 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.2

CVSS3.1

CVE-2026-34535 - iccDEV: SEGV in CIccTagArray::Cleanup()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a segmentation fault (SEGV) in CIccTagArray::Cleanup(). The issue is observable under UBSan/ASan as misaligned member access / misaligned pointer …

πŸ“… Published: March 31, 2026, 9:58 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.
Total resulsts: 341926
Page 45 of 34,193
Β« previous page Β» next page
Filters