7.1

CVSS3.1

CVE-2026-24409 - iccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlFloatNum<>::ParseXml()

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior and Null Pointer Deference in CIccTagXmlFloatNum<>::ParseXml(). This occurs when user-controllable input is unsafely incorporated in…

📅 Published: Jan. 24, 2026, 1:09 a.m. 🔄 Last Modified: April 18, 2026, 3:15 p.m.

7.1

CVSS3.1

CVE-2026-24407 - iccDEV has Undefined Behavior in icSigCalcOp()

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior in icSigCalcOp(). This occurs when user-controllable input is unsafely incorporated into ICC profile data or other structured binary…

📅 Published: Jan. 24, 2026, 1:05 a.m. 🔄 Last Modified: April 18, 2026, 3:15 p.m.

8.8

CVSS3.1

CVE-2026-24406 - iccDEV has Heap Buffer Overflow in CIccTagNamedColor2::SetSize()

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buffer Overflow vulnerability in CIccTagNamedColor2::SetSize(). This occurs when user-controllable input is unsafely incorporated into ICC profi…

📅 Published: Jan. 24, 2026, 1:02 a.m. 🔄 Last Modified: April 18, 2026, 7 p.m.

8.8

CVSS3.1

CVE-2026-24405 - iccDEV has Heap Buffer Overflow in CIccMpeCalculator::Read()

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buffer Overflow vulnerability in CIccMpeCalculator::Read(). This occurs when user-controllable input is unsafely incorporated into ICC profile d…

📅 Published: Jan. 24, 2026, 12:59 a.m. 🔄 Last Modified: April 18, 2026, 3:15 p.m.

7.1

CVSS3.1

CVE-2026-24404 - iccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType()

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CIccXmlArrayType() contains a Null Pointer Dereference and Undefined Behavior vulnerability. This occurs when user-controllable input is unsafely incorp…

📅 Published: Jan. 24, 2026, 12:55 a.m. 🔄 Last Modified: April 18, 2026, 3 a.m.

7.1

CVSS3.1

CVE-2026-24403 - iccDEV Undefined Behavior in CIccProfile::CheckHeader() Leads to Integer Overflow

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, an integer overflow vulnerability exists in icValidateStatus CIccProfile::CheckHeader() when user-controllable input is incorporated into profile data u…

📅 Published: Jan. 24, 2026, 12:46 a.m. 🔄 Last Modified: April 18, 2026, 3:15 a.m.

9.8

CVSS3.1

CVE-2026-22583 - Argument Injection in Salesforce Marketing Cloud Engagement CloudPagesUrl Module

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.

📅 Published: Jan. 24, 2026, 12:20 a.m. 🔄 Last Modified: April 18, 2026, 3:15 a.m.

9.8

CVSS3.1

CVE-2026-22582 - Improper Neutralization of Argument Delimiters in a Command Leading to Web Services Protocol Manipu…

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.

📅 Published: Jan. 24, 2026, 12:19 a.m. 🔄 Last Modified: April 18, 2026, 3:15 a.m.

9.8

CVSS3.1

CVE-2026-22586 - Hard‑coded Cryptographic Key Allows Web Services Protocol Manipulation in Salesforce Marketing Clou…

Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January …

📅 Published: Jan. 24, 2026, 12:17 a.m. 🔄 Last Modified: April 18, 2026, 3:15 a.m.

9.8

CVSS3.1

CVE-2026-22585 - Risky Cryptographic Algorithm Enables Web Services Protocol Manipulation in Salesforce Marketing Cl…

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagem…

📅 Published: Jan. 24, 2026, 12:15 a.m. 🔄 Last Modified: April 18, 2026, 3:15 p.m.
Total resulsts: 348413
Page 1885 of 34,842
« previous page » next page
Filters