CVE-2026-21494 – iccDEV has heap buffer overflow in CIccTagLut8::Validate()
CVE ID : CVE-2026-21494
Published : Jan. 6, 2026, 7:16 p.m. | 1 hour, 11 minutes ago
Description : iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It results in heap buffer overflow in `CIccTagLut8::Validate()`. Version 2.3.1.2 contains a patch. No known workarounds are available.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…