Vulnerabilidades em InternationalColorConsortium

104 resultados
Análise Vexday

O portfólio de vulnerabilidades associado ao International Color Consortium reúne 104 CVEs catalogadas, com uma única entrada de severidade crítica e nenhuma PoC pública disponível, o que limita o vetor de exploração imediata. A taxa de exploração ativa é nula — nenhuma entrada consta no catálogo KEV da CISA —, posicionando-se abaixo da média geral do catálogo, o que sugere risco operacional contido no momento. Ainda assim, o volume de 20 CVEs surgidas nos últimos 90 dias merece atenção, indicando ritmo elevado de descobertas recentes. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que tende a se manifestar em componentes de processamento de dados como perfis de cor, e a CVE mais perigosa identificada atualmente, CVE-2026-22861, apresenta EPSS de 0,0059, refletindo baixa probabilidade de exploração no curto prazo segundo os modelos preditivos vigentes.

CVE-2026-22861HIGHiccDEV has a heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cppEPSS 0.6%CVE-2026-24406HIGHiccDEV has Heap Buffer Overflow in CIccTagNamedColor2::SetSize()EPSS 0.5%CVE-2026-24405HIGHiccDEV has Heap Buffer Overflow in CIccMpeCalculator::Read()EPSS 0.5%CVE-2026-24412HIGHiccDEV has Heap Buffer Overflow in icCurvesFromXml()EPSS 0.5%CVE-2026-24404HIGHiccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType()EPSS 0.4%CVE-2026-24407HIGHiccDEV has Undefined Behavior in icSigCalcOp()EPSS 0.4%CVE-2026-24403HIGHiccDEV Undefined Behavior in CIccProfile::CheckHeader() Leads to Integer OverflowEPSS 0.4%CVE-2026-21675CRITICALiccDEV has a Use After Free vulnerability in CIccCmm class via improper hint manager object deletionEPSS 0.4%CVE-2026-21507HIGHiccDEV is Vulnerable to Denial of Service via Infinite Loop in CalcProfileID()EPSS 0.4%CVE-2026-22255HIGHiccDEV has heap-buffer-overflow in CIccCLUT::Init() at IccProfLib/IccTagLut.cppEPSS 0.4%CVE-2026-21676HIGHiccDEV has a Heap-based Buffer Overflow in its CIccMBB::Validate() functionEPSS 0.3%CVE-2026-21679HIGHiccDEV has heap-buffer-overflow vulnerability in CIccLocalizedUnicode::GetText()EPSS 0.3%CVE-2026-22047HIGHiccDEV has heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cppEPSS 0.3%CVE-2026-21688HIGHiccDEV has Type Confusion in SIccCalcOp::ArgsPushed() at IccProfLib/IccMpeCalc.cppEPSS 0.3%CVE-2026-21682HIGHiccDEV has heap-buffer-overflow in CIccXmlArrayType::ParseText()EPSS 0.3%CVE-2026-21693HIGHiccDEV has Type Confusion in CIccSegmentedCurveXml::ToXml() at IccXML/IccLibXML/IccMpeXml.cppEPSS 0.3%CVE-2026-21677HIGHiccDEV has Undefined Behavior in CIccCLUT::Init()EPSS 0.3%CVE-2026-21485HIGHiccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()EPSS 0.3%CVE-2026-21692HIGHiccDEV has Type Confusion in ToXmlCurve() at IccXML/IccLibXML/IccMpeXml.cppEPSS 0.3%CVE-2026-24409HIGHiccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlFloatNum<>::ParseXml()EPSS 0.3%