CVE-2026-25502

HIGH

Color Iccdev < 2.3.1.2 - Out-of-Bounds Write

Title source: rule

Description

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, stack-based buffer overflow in icFixXml() function when processing malformed ICC profiles, allows potential arbitrary code execution through crafted NamedColor2 tags. This issue has been patched in version 2.3.1.2.

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 1.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-121 CWE-787
Status published

Affected Products (1)

color/iccdev < 2.3.1.2

Timeline

Published Feb 03, 2026
Tracked Since Feb 18, 2026