iccDEV是International Color Consortium开源的一个颜色配置代码库。 iccDEV 2.3.1.1及之前版本存在安全漏洞,该漏洞源于CIccTagXmlFloatNum<>::ParseXml存在未定义行为和空指针取消引用,可能导致拒绝服务、数据操纵或代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| InternationalColorConsortium | iccDEV | < 2.3.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24412 | 8.8 HIGH | iccDEV has Heap Buffer Overflow in icCurvesFromXml() |
| CVE-2026-24406 | 8.8 HIGH | iccDEV has Heap Buffer Overflow in CIccTagNamedColor2::SetSize() |
| CVE-2026-24405 | 8.8 HIGH | iccDEV has Heap Buffer Overflow in CIccMpeCalculator::Read() |
| CVE-2026-24411 | 7.1 HIGH | iccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlSegmentedCurve::ToXm |
| CVE-2026-24410 | 7.1 HIGH | iccDEV has Undefined Behavior and Null Pointer Deference in CIccProfileXml::ParseBasic() |
| CVE-2026-24407 | 7.1 HIGH | iccDEV has Undefined Behavior in icSigCalcOp() |
| CVE-2026-24404 | 7.1 HIGH | iccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType() |
| CVE-2026-24403 | 7.1 HIGH | iccDEV Undefined Behavior in CIccProfile::CheckHeader() Leads to Integer Overflow |
No comments yet