iccDEV是International Color Consortium开源的一个颜色配置代码库。 iccDEV 2.3.1.5之前版本存在代码问题漏洞,该漏洞源于CIccTagXmlStruct::ParseTag()函数存在空指针取消引用,可能导致分段违规或拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| InternationalColorConsortium | iccDEV | < 2.3.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-31796 | 7.8 HIGH | iccDEV has a heap-based buffer overflow in icCurvesFromXml() |
| CVE-2026-31795 | 7.8 HIGH | iccDEV has a stack buffer overflow write in CIccXform3DLut::Apply() |
| CVE-2026-30978 | 7.8 HIGH | Heap-use-after-free in CIccCmm::AddXform() |
| CVE-2026-30979 | 7.8 HIGH | iccDEV has a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp() |
| CVE-2026-30985 | 7.8 HIGH | iccDEV has a heap-based buffer overflow write in CIccMatrixMath::SetRange() |
| CVE-2026-30983 | 7.8 HIGH | iccDEV has a stack buffer overflow in icFixXml() |
| CVE-2026-30987 | 7.8 HIGH | iccDEV has a stack buffer overflow in CIccTagNum<(icTagTypeSignature)>::GetValues() |
| CVE-2026-31797 | 6.1 MEDIUM | iccDEV has a heap out-of-bounds read in CTiffImg::ReadLine() |
| CVE-2026-30982 | 6.1 MEDIUM | iccDEV has a heap out-of-bounds read in CIccPcsXform::pushXYZConvert() |
| CVE-2026-30984 | 6.1 MEDIUM | iccDEV has a heap out-of-bounds read in CIccCalculatorFunc::ApplySequence() |
| CVE-2026-30981 | 6.1 MEDIUM | iccDEV has a heap-buffer-overflow read in CIccXmlArrayType<> |
| CVE-2026-31793 | 5.5 MEDIUM | iccDEV has a SEGV in CIccCalculatorFunc::ApplySequence() |
| CVE-2026-31794 | 5.5 MEDIUM | iccDEV has a SEGV in CIccCLUT::Interp3d() |
| CVE-2026-30986 | 5.5 MEDIUM | iccDEV has a heap-based buffer overflow write in CIccCLUT::Interp3d() |
| CVE-2026-30980 | 5.5 MEDIUM | iccDEV has a stack overflow in CIccBasicStructFactory::CreateStruct() |
No comments yet