PT-2026-24361 · Iccdev · Iccdev

Xsscx

·

Publicado

2026-03-10

·

Atualizado

2026-03-14

·

CVE-2026-31796

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.5
Description iccDEV is a set of libraries and tools for working with ICC color management profiles. A heap-based buffer overflow exists in the icCurvesFromXml() function, potentially leading to heap memory corruption or a crash.
Recommendations Update to version 2.3.1.5 or later.

Exploit

Correção

Memory Corruption

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-31796
GHSA-MV6H-VPCG-PWFX

Produtos afetados

Iccdev