6.2

CVSS3.1

CVE-2026-34551 - iccDEV: NPD in CIccTagLut16::Write()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a null-pointer dereference (NPD) in CIccTagLut16::Write() can be triggered when processing a crafted ICC profile (embedded in a TIFF and extracted during iccTiffDump). This issue h…

πŸ“… Published: March 31, 2026, 10:14 p.m. πŸ”„ Last Modified: April 20, 2026, 2:33 p.m.

6.2

CVSS3.1

CVE-2026-34550 - iccDEV: UB at IccIO.cpp

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccProfLib/IccIO.cpp caused by an implicit conversion from a negative signed integer to size_t (unsigned), which changes the value.…

πŸ“… Published: March 31, 2026, 10:12 p.m. πŸ”„ Last Modified: April 20, 2026, 2:33 p.m.

6.2

CVSS3.1

CVE-2026-34549 - iccDEV: UB at IccUtil.cpp

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccUtil.cpp triggered by a crafted input profile. Under UndefinedBehaviorSanitizer, the issue is reported as invalid left shift ope…

πŸ“… Published: March 31, 2026, 10:11 p.m. πŸ”„ Last Modified: April 20, 2026, 2:33 p.m.

6.2

CVSS3.1

CVE-2026-34548 - iccDEV: UB at IccUtilXml.cpp

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in the XML conversion tooling path (iccToXml) caused by an implicit conversion from a negative signed integer to icUInt32Number (unsig…

πŸ“… Published: March 31, 2026, 10:09 p.m. πŸ”„ Last Modified: April 20, 2026, 2:32 p.m.

6.2

CVSS3.1

CVE-2026-34547 - iccDEV: UB at IccUtil.cpp

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, an Undefined Behavior (UB) condition in IccUtil.cpp can be triggered by a crafted ICC profile when running iccDumpProfile. This issue has been patched in version 2.3.1.6.

πŸ“… Published: March 31, 2026, 10:08 p.m. πŸ”„ Last Modified: April 20, 2026, 2:31 p.m.

6.2

CVSS3.1

CVE-2026-34546 - iccDEV: UB at TiffImg.h

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted TIFF input can trigger Undefined Behavior (UB) due to division by zero in the TIFF handling code paths used by iccTiffDump. This issue has been patched in version 2.3.1.6.

πŸ“… Published: March 31, 2026, 10:06 p.m. πŸ”„ Last Modified: April 20, 2026, 2:32 p.m.

6.2

CVSS3.1

CVE-2026-34542 - iccDEV: SBO in CIccCalculatorFunc::Apply()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a stack-buffer-overflow (SBO) in CIccCalculatorFunc::Apply() when processed via iccApplyNamedCmm. Under AddressSanitizer, the failure is reported …

πŸ“… Published: March 31, 2026, 10:05 p.m. πŸ”„ Last Modified: April 20, 2026, 2:31 p.m.

6.2

CVSS3.1

CVE-2026-34541 - iccDEV: UB in CIccCombinedConnectionConditions::CIccCombinedConnectionConditions()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger Undefined Behavior (UB) via a null-pointer member call in CIccCombinedConnectionConditions::CIccCombinedConnectionConditions() (reported by UBSan …

πŸ“… Published: March 31, 2026, 10:04 p.m. πŸ”„ Last Modified: April 20, 2026, 1:54 p.m.

6.2

CVSS3.1

CVE-2026-34540 - iccDEV: HBO in icMemDump()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a heap-buffer-overflow (HBO) in icMemDump() when iccDumpProfile attempts to dump/describe malformed tag contents. The issue is observable under Ad…

πŸ“… Published: March 31, 2026, 10:03 p.m. πŸ”„ Last Modified: April 20, 2026, 1:53 p.m.

6.2

CVSS3.1

CVE-2026-34539 - iccDEV: HBO in CTiffImg::WriteLine()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile and TIFF input can trigger a heap-buffer-overflow (HBO) in CTiffImg::WriteLine(). The issue is observable under AddressSanitizer as an out-of-bounds heap read…

πŸ“… Published: March 31, 2026, 10:01 p.m. πŸ”„ Last Modified: April 20, 2026, 1:52 p.m.
Total resulsts: 349182
Page 766 of 34,919
Β« previous page Β» next page
Filters