Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,237
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 66 CVEs
CVE-2026-25634 HIGH - 7.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to 2.3.1.4, SrcPixel and DestPixel stack buffers overlap in CIccTagMultiProcessElement::Apply() int IccTagMPE.cpp. This vulnerability is fixed in 2.3.1.4...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Feb 06, 2026
Source: NVD
CVE-2026-25585 HIGH - 7.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a vulnerability IccCmm.cpp:5793 when reading through index during ICC profile processing. The malformed ICC profile triggers...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Feb 04, 2026
Source: NVD
CVE-2026-25584 HIGH - 7.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a stack-buffer-overflow vulnerability in CIccTagFloatNum<>::GetValues(). This is triggered when processing a malformed...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Feb 04, 2026
Source: NVD
CVE-2026-25583 HIGH - 7.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a heap buffer overflow vulnerability in CIccFileIO::Read8() when processing malformed ICC profile files via unchecked fread ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Feb 04, 2026
Source: NVD
CVE-2026-25582 HIGH - 7.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a heap buffer overflow (read) vulnerability in CIccIO::WriteUInt16Float() when converting malformed XML to ICC profiles via ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Feb 04, 2026
Source: NVD
CVE-2026-25503 HIGH - 7.1

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, type confusion allowed malformed ICC profiles to trigger undefined behavior when loading invalid icImageEncodingType values causing d...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Feb 03, 2026
Source: NVD
CVE-2026-25502 HIGH - 7.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, stack-based buffer overflow in icFixXml() function when processing malformed ICC profiles, allows potential arbitrary code execution ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Feb 03, 2026
Source: NVD
CVE-2026-24856 HIGH - 7.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Versions prior to 2.3.1.2 have an undefined behavior issue when floating-point NaN values are converted to unsigned short integer types during ICC profile XML ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 28, 2026
Source: NVD
CVE-2026-24852 MEDIUM - 6.1

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, a heap buffer over-read when the strlen() function attempts to read a non-null-terminated buffer potentially leaking heap memory cont...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 28, 2026
Source: NVD
CVE-2026-24412 HIGH - 8.8

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have aHeap Buffer Overflow vulnerability in the CIccTagXmlSegmentedCurve::ToXml() function. This occurs when user-controllable input is unsafely incorporated...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 24, 2026
Source: NVD
CVE-2026-24411 HIGH - 7.1

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior in CIccTagXmlSegmentedCurve::ToXml(). This occurs when user-controllable input is unsafely incorporated into ICC profile data or othe...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 24, 2026
Source: NVD
CVE-2026-24410 HIGH - 7.1

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior and Null Pointer Deference in CIccProfileXml::ParseBasic(). This occurs when user-controllable input is unsafely incorporated into IC...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 24, 2026
Source: NVD
CVE-2026-24409 HIGH - 7.1

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior and Null Pointer Deference in CIccTagXmlFloatNum<>::ParseXml(). This occurs when user-controllable input is unsafely incorporat...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 24, 2026
Source: NVD
CVE-2026-24407 HIGH - 7.1

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior in icSigCalcOp(). This occurs when user-controllable input is unsafely incorporated into ICC profile data or other structured binary ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 24, 2026
Source: NVD
CVE-2026-24406 HIGH - 8.8

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buffer Overflow vulnerability in CIccTagNamedColor2::SetSize(). This occurs when user-controllable input is unsafely incorporated into ICC profil...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 24, 2026
Source: NVD
CVE-2026-24405 HIGH - 8.8

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buffer Overflow vulnerability in CIccMpeCalculator::Read(). This occurs when user-controllable input is unsafely incorporated into ICC profile da...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 24, 2026
Source: NVD
CVE-2026-24404 HIGH - 7.1

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CIccXmlArrayType() contains a Null Pointer Dereference and Undefined Behavior vulnerability. This occurs when user-controllable input is unsafely incorpo...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 24, 2026
Source: NVD
CVE-2026-24403 HIGH - 7.1

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, an integer overflow vulnerability exists in icValidateStatus CIccProfile::CheckHeader() when user-controllable input is incorporated into profile data un...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Jan 24, 2026
Source: NVD
CVE-2026-22861 HIGH - 8.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Prior to 2.3.1.2, There is a heap-based buffer overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp. This vulnerabi...

Vendor: color
Product: iccdev
Published: Jan 13, 2026
Source: NVD
CVE-2026-22255 HIGH - 8.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow vulnerability in `CIccCLUT::Init()` at `IccProfLib/IccTagLut.cpp`. This ...

Vendor: color
Product: iccdev
Published: Jan 08, 2026
Source: NVD