Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2883 articles · 106447 vulns · 38/41 feeds (7d)
← Back to list
6.2
CVE-2026-34554EXPLOITEDPATCHED
internationalcolorconsortium · iccdev

iccDEV: HBO in CIccApplyCmmSearch::costFunc()

Description

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a heap-buffer-overflow (HBO) in CIccApplyCmmSearch::costFunc() can be triggered via malformed JSON configuration input to the iccApplySearch tool. AddressSanitizer reports an out-of-bounds READ of size 8 originating from CIccApplyCmmSearch::costFunc(CIccSearchVec&) at IccProfLib/IccCmmSearch.cpp:112:5. This issue has been patched in version 2.3.1.6.

Affected Products

VendorProductVersions
internationalcolorconsortiumiccdev< 2.3.1.6, 2.3.1.1, 2.3.1.2, 2.3.1.3, 2.3.1.4, 2.3.1.5

References

  • https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-hqc7-5pgc-9672(x_refsource_CONFIRM)
  • https://github.com/InternationalColorConsortium/iccDEV/issues/700(x_refsource_MISC)
  • https://github.com/InternationalColorConsortium/iccDEV/pull/738(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB10h ago
CVE-2026-34554 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 JSON Configuration IccCmmSearch.cpp costFunc out-of-bounds (ID 700)
→ No new info (linked only)
CVSS 3.16.2 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2.3.1.6
CWECWE-125
PublishedMar 31, 2026
Last enriched10h agov2
Trending Score45
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-34539EXP
iccDEV: HBO in CTiffImg::WriteLine()
Trending: 48
CRITICALCVE-2026-34540EXP
iccDEV: HBO in icMemDump()
Trending: 48
CRITICALCVE-2026-34535EXP
iccDEV: SEGV in CIccTagArray::Cleanup()
Trending: 47
CRITICALCVE-2026-34534EXP
iccDEV: HBO in CIccMpeSpectralMatrix::Describe()
Trending: 47
HIGHCVE-2026-34533EXP
iccDEV: UB in CIccCalculatorFunc::ApplySequence()
Trending: 45

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Mar 31, 2026
Actively Exploited
Mar 31, 2026
Patch Available
Mar 31, 2026
Discovered by ZDM
Mar 31, 2026
Updated: affectedVersions, severity, activelyExploited, patchAvailable
Apr 1, 2026

Version History

v2
Last enriched 10h ago
v2Tier C10h ago

Updated affected versions to include 2.3.1.1 through 2.3.1.5, changed severity to HIGH, and noted that the vulnerability is actively exploited.

affectedVersionsseverityactivelyExploitedpatchAvailable
via VulDB
v114h ago

Initial creation