CVE-2026-21504

MEDIUM

iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in ToneMap Parser

Title source: llm
STIX 2.1

Description

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap buffer overflow in the ToneMap parser. This issue has been patched in version 2.3.1.2.

Scores

CVSS v3 6.6
EPSS 0.0018
EPSS Percentile 7.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-122 CWE-193 CWE-787
Status published
Products (1)
color/iccdev < 2.3.1.2
Published Jan 07, 2026
Tracked Since Feb 18, 2026