iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.
Metrics
Affected Vendors & Products
References
History
Wed, 07 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
|
| Vendors & Products |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
Tue, 06 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2. | |
| Title | iccDEV has Type Confusion during XML Curve Serialization | |
| Weaknesses | CWE-188 CWE-703 CWE-843 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-06T14:33:17.289Z
Reserved: 2025-12-29T14:34:16.006Z
Link: CVE-2026-21493
Updated: 2026-01-06T14:32:40.723Z
Status : Received
Published: 2026-01-06T15:15:44.983
Modified: 2026-01-06T15:15:44.983
Link: CVE-2026-21493
No data.
OpenCVE Enrichment
Updated: 2026-01-07T10:36:27Z