MEDIUM🇬🇧 English

CVE-2026-21502

CVSS 5.5v3.1pub. 2026-01-07upd. 2026-01-09

iccDEV to zestaw bibliotek i narzędzi umożliwiających interakcję, manipulację i stosowanie profili zarządzania kolorami ICC. Przed wersją 2.3.1.2, iccDEV był podatny na NULL pointer dereference przez parser tagów XML. Problem został naprawiony w wersji 2.3.1.2.

Pokaż oryginał (EN)

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML tag parser. This issue has been patched in version 2.3.1.2.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  • Color Iccdev

    APP
    Color
    < 2.3.1.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-21675CRITICAL9.8PL ✓ten sam produkt

Use-after-free w iccDEV — podatność w funkcji CIccXform::Create()

CVE-2026-30978HIGH7.8ten sam produkt

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5,...

CVE-2026-30983HIGH7.8ten sam produkt

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5,...

CVE-2026-30979HIGH7.8ten sam produkt

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5,...

CVE-2026-30985HIGH7.8ten sam produkt

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5,...