CVE-2026-21493 - CERT CVE
ID CVE-2026-21493
Sažetak iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.
Reference
CVSS
Base: 6.6
Impact: 4.7
Exploitability:1.8
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW HIGH
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Zadnje važnije ažuriranje 14-01-2026 - 18:46
Objavljeno 06-01-2026 - 15:15