MEDIUM🇬🇧 English

CVE-2026-21498

CVSS 5.5v3.1pub. 2026-01-07upd. 2026-01-09

iccDEV dostarcza zestaw bibliotek i narzędzi umożliwiających interakcję, manipulację i stosowanie profilów zarządzania kolorami ICC. Przed wersją 2.3.1.2 iccDEV jest podatny na NULL pointer dereference poprzez parser kalkulatora XML. Problem został naprawiony w wersji 2.3.1.2.

Pokaż oryginał (EN)

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML calculator parser. This issue has been patched in version 2.3.1.2.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  • Color Iccdev

    APP
    Color
    < 2.3.1.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-21675CRITICAL9.8PL ✓ten sam produkt

Use-after-free w iccDEV — podatność w funkcji CIccXform::Create()

CVE-2026-30978HIGH7.8ten sam produkt

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5,...

CVE-2026-30983HIGH7.8ten sam produkt

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5,...

CVE-2026-30979HIGH7.8ten sam produkt

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5,...

CVE-2026-30985HIGH7.8ten sam produkt

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5,...