Color Security Vulnerabilities (CVEs)

Track 57 security vulnerabilities affecting Color products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

1 Critical
34 High
21 Medium
1 Low
🔔 Get Alerts for Color
CVE-2026-27692 7.1

A heap buffer overflow vulnerability in iccDEV allows reading past allocated memory boundaries when parsing ICC profile XML text description tags. Thi...

Feb 25, 2026
CVE-2026-25634 7.8

This CVE describes a buffer overlap vulnerability in iccDEV's CIccTagMultiProcessElement::Apply() function where SrcPixel and DestPixel stack buffers ...

Feb 6, 2026
CVE-2026-25585 7.8

This vulnerability in iccDEV allows attackers to trigger an out-of-bounds read by providing a malformed ICC color profile. This can lead to memory dis...

Feb 4, 2026
CVE-2026-25582 7.8

A heap buffer overflow vulnerability in iccDEV's CIccIO::WriteUInt16Float() function allows attackers to cause denial of service or potentially execut...

Feb 4, 2026
CVE-2026-25583 7.8

A heap buffer overflow vulnerability exists in iccDEV's CIccFileIO::Read8() function when processing malformed ICC profile files. This allows attacker...

Feb 4, 2026
CVE-2026-25584 7.8

A stack-buffer-overflow vulnerability in iccDEV's CIccTagFloatNum::GetValues() function allows memory corruption when processing malformed ICC color p...

Feb 4, 2026
CVE-2026-24856 7.8

A memory corruption vulnerability in iccDEV library versions before 2.3.1.2 allows arbitrary code execution when processing malicious ICC color profil...

Jan 28, 2026
CVE-2026-24852 6.1

A heap buffer over-read vulnerability in iccDEV library versions before 2.3.1.2 allows attackers to potentially leak heap memory contents and cause ap...

Jan 28, 2026
CVE-2026-24410 7.1

CVE-2026-24410 is a vulnerability in iccDEV's ICC color management profile libraries where improper input validation in CIccProfileXml::ParseBasic() l...

Jan 24, 2026
CVE-2026-24411 7.1

CVE-2026-24411 is an undefined behavior vulnerability in iccDEV's CIccTagXmlSegmentedCurve::ToXml() function that allows attackers to perform denial o...

Jan 24, 2026
CVE-2026-24412 8.8

A heap buffer overflow vulnerability in iccDEV's CIccTagXmlSegmentedCurve::ToXml() function allows attackers to execute arbitrary code or cause denial...

Jan 24, 2026
CVE-2026-24409 7.1

This vulnerability in iccDEV allows attackers to exploit undefined behavior and null pointer dereferences when processing user-controlled ICC color pr...

Jan 24, 2026
CVE-2026-24406 8.8

CVE-2026-24406 is a heap buffer overflow vulnerability in iccDEV's CIccTagNamedColor2::SetSize() function that allows attackers to execute arbitrary c...

Jan 24, 2026
CVE-2026-24407 7.1

CVE-2026-24407 is an undefined behavior vulnerability in iccDEV's icSigCalcOp() function that allows attackers to manipulate ICC color profile data. S...

Jan 24, 2026
CVE-2026-24403 7.1

An integer overflow vulnerability in iccDEV's CIccProfile::CheckHeader() function allows attackers to trigger memory corruption or denial of service b...

Jan 24, 2026
CVE-2026-24404 7.1

A null pointer dereference vulnerability in iccDEV's CIccXmlArrayType() function allows attackers to cause denial of service, manipulate data, bypass ...

Jan 24, 2026
CVE-2026-24405 8.8

A heap buffer overflow vulnerability in iccDEV's CIccMpeCalculator::Read() function allows attackers to execute arbitrary code or cause denial of serv...

Jan 24, 2026
CVE-2026-22255 8.8

A heap-buffer-overflow vulnerability in iccDEV's CIccCLUT::Init() function allows attackers to execute arbitrary code or cause denial of service by pr...

Jan 8, 2026
CVE-2026-22047 8.8

A heap-buffer-overflow vulnerability in iccDEV's SIccCalcOp::Describe() function allows attackers to execute arbitrary code or cause denial of service...

Jan 7, 2026
CVE-2026-21688 8.8

A type confusion vulnerability in iccDEV's SIccCalcOp::ArgsPushed() function allows attackers to potentially execute arbitrary code or cause denial of...

Jan 7, 2026
CVE-2026-21689 6.5

A type confusion vulnerability in iccDEV's CIccProfileXml::ParseBasic() function allows attackers to potentially execute arbitrary code or cause denia...

Jan 7, 2026
CVE-2026-21690 6.3

CVE-2026-21690 is a type confusion vulnerability in iccDEV's CIccTagXmlTagData::ToXml() function that could allow memory corruption when processing ma...

Jan 7, 2026
CVE-2026-21691 5.4

A type confusion vulnerability in iccDEV's CIccTag::IsTypeCompressed() function allows attackers to potentially execute arbitrary code or cause denial...

Jan 7, 2026
CVE-2026-21692 8.8

A type confusion vulnerability in iccDEV's ToXmlCurve() function allows attackers to potentially execute arbitrary code or cause denial of service by ...

Jan 7, 2026
CVE-2026-21693 8.8

CVE-2026-21693 is a type confusion vulnerability in iccDEV's CIccSegmentedCurveXml::ToXml() function that could allow memory corruption when processin...

Jan 7, 2026
CVE-2026-22046 8.8

A heap-buffer-overflow vulnerability in iccDEV's CIccProfileXml::ParseBasic() function allows attackers to execute arbitrary code or cause denial of s...

Jan 7, 2026
CVE-2026-21683 8.8

A type confusion vulnerability in iccDEV's CIccEvalCompare::EvaluateProfile() function allows attackers to execute arbitrary code or cause denial of s...

Jan 7, 2026
CVE-2026-21684 7.1

This vulnerability involves undefined behavior in the CIccTagSpectralViewingConditions() function of the iccDEV library, which could lead to crashes, ...

Jan 7, 2026
CVE-2026-21685 7.1

This vulnerability involves undefined behavior in the CIccTagLut16::Read() function of the iccDEV library, which could lead to memory corruption when ...

Jan 7, 2026
CVE-2026-21686 7.1

This vulnerability involves undefined behavior in the CIccTagLutAtoB::Validate() function of the iccDEV library, which could lead to crashes, memory c...

Jan 7, 2026
CVE-2026-21687 7.1

CVE-2026-21687 is an undefined behavior vulnerability in the CIccTagCurve constructor of the iccDEV library that processes ICC color profiles. This co...

Jan 7, 2026
CVE-2026-21681 7.1

CVE-2026-21681 is an undefined behavior runtime error in iccDEV library versions before 2.3.1.2 that could lead to crashes or potentially arbitrary co...

Jan 7, 2026
CVE-2026-21682 8.8

CVE-2026-21682 is a heap buffer overflow vulnerability in iccDEV's CIccXmlArrayType::ParseText() function that allows attackers to execute arbitrary c...

Jan 7, 2026
CVE-2026-21678 7.8

CVE-2026-21678 is a heap-buffer-overflow vulnerability in the IccTagXml() function of iccDEV, a library for ICC color management profiles. It allows a...

Jan 7, 2026
CVE-2026-21679 8.8

CVE-2026-21679 is a heap buffer overflow vulnerability in iccDEV's CIccLocalizedUnicode::GetText() function that could allow attackers to execute arbi...

Jan 7, 2026
CVE-2026-21680 6.5

A NULL pointer dereference vulnerability in iccDEV library versions before 2.3.1.2 can cause application crashes or denial of service when processing ...

Jan 7, 2026
CVE-2026-21501 5.5

CVE-2026-21501 is a stack overflow vulnerability in iccDEV's calculator parser that could allow attackers to execute arbitrary code or cause denial of...

Jan 7, 2026
CVE-2026-21502 5.5

CVE-2026-21502 is a NULL pointer dereference vulnerability in iccDEV's XML tag parser that can cause application crashes or denial of service. This af...

Jan 7, 2026
CVE-2026-21503 6.1

This vulnerability in iccDEV allows attackers to trigger undefined behavior by exploiting a null pointer passed to memcpy() in CIccTagSparseMatrixArra...

Jan 7, 2026
CVE-2026-21504 6.6

CVE-2026-21504 is a heap buffer overflow vulnerability in the ToneMap parser of iccDEV color management libraries. This allows attackers to execute ar...

Jan 7, 2026
CVE-2026-21505 5.5

CVE-2026-21505 is an undefined behavior vulnerability in iccDEV color management libraries caused by an invalid enum value. This could potentially lea...

Jan 7, 2026
CVE-2026-21506 5.5

This CVE describes a null pointer dereference vulnerability in iccDEV's CIccProfileXml::ParseBasic() function that can cause denial of service. Attack...

Jan 7, 2026
CVE-2026-21495 5.5

A division by zero vulnerability exists in iccDEV's TIFF Image Reader component, which could cause application crashes or denial of service when proce...

Jan 7, 2026
CVE-2026-21496 5.5

CVE-2026-21496 is a NULL pointer dereference vulnerability in iccDEV's signature parser that can cause denial of service. This affects applications us...

Jan 7, 2026
CVE-2026-21497 5.5

A NULL pointer dereference vulnerability in iccDEV's unknown tag parser allows attackers to cause denial of service by crashing applications using the...

Jan 7, 2026
CVE-2026-21498 5.5

A NULL pointer dereference vulnerability exists in iccDEV's XML calculator parser before version 2.3.1.2. This vulnerability could cause application c...

Jan 7, 2026
CVE-2026-21499 5.5

CVE-2026-21499 is a NULL pointer dereference vulnerability in iccDEV's XML parser that can cause application crashes or denial of service. This affect...

Jan 7, 2026
CVE-2026-21500 5.5

CVE-2026-21500 is a stack overflow vulnerability in iccDEV's XML calculator macro expansion that could allow attackers to execute arbitrary code or ca...

Jan 7, 2026
CVE-2026-21492 5.5

CVE-2026-21492 is a NULL pointer dereference vulnerability in iccDEV library versions before 2.3.1.2 that could cause application crashes or denial of...

Jan 6, 2026
CVE-2026-21494 6.1

A heap buffer overflow vulnerability in iccDEV library's CIccTagLut8::Validate() function allows attackers to execute arbitrary code or cause denial o...

Jan 6, 2026

Why Monitor Color Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 57+ known vulnerabilities affecting Color products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Color packages in under 60 seconds. No agents required - completely agentless scanning that works across Color deployments.

Free vulnerability database: Access detailed information about every Color CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Color CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Color CVEs Free