Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 10 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Color
Color iccdev |
|
| CPEs | cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Color
Color iccdev |
Wed, 04 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
|
| Vendors & Products |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
Tue, 03 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, stack-based buffer overflow in icFixXml() function when processing malformed ICC profiles, allows potential arbitrary code execution through crafted NamedColor2 tags. This issue has been patched in version 2.3.1.2. | |
| Title | iccDEV is vulnerable to stack-buffer-overflow in icFixXml() | |
| Weaknesses | CWE-121 CWE-787 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-04T20:09:50.566Z
Reserved: 2026-02-02T18:21:42.485Z
Link: CVE-2026-25502
Updated: 2026-02-04T20:09:42.444Z
Status : Analyzed
Published: 2026-02-03T19:16:26.963
Modified: 2026-02-10T16:18:43.340
Link: CVE-2026-25502
No data.
OpenCVE Enrichment
Updated: 2026-02-04T12:05:21Z