CVE-2026-21493
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.6
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
- EPSS probability
- 0.18%
- CWE
- CWE-188, CWE-703, CWE-843
- Published
- 2026-01-06
- Last modified
- 2026-03-12
Affected products
- InternationalColorConsortium iccDEV
Weakness type
Related vulnerabilities
- CVE-2026-68860 — Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory...