CVE-2026-25502

HIGH

iccdev < 2.3.1.2 - Stack-based Buffer Overflow in icFixXml() via Malformed NamedColor2 Tag

Title source: llm
STIX 2.1

Description

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, stack-based buffer overflow in icFixXml() function when processing malformed ICC profiles, allows potential arbitrary code execution through crafted NamedColor2 tags. This issue has been patched in version 2.3.1.2.

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 10.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-121 CWE-787
Status published
Products (1)
color/iccdev < 2.3.1.2
Published Feb 03, 2026
Tracked Since Feb 18, 2026