Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2725 articles · 106376 vulns · 38/41 feeds (7d)
← Back to list
6.2
CVE-2026-34539EXPLOITEDPATCHED
internationalcolorconsortium · iccdev

iccDEV: HBO in CTiffImg::WriteLine()

Description

A vulnerability categorized as critical has been discovered in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5. This impacts the function CTiffImg::WriteLine of the component ICC Color Profile Handler. Such manipulation leads to heap-based buffer overflow. The attack can be launched remotely.

Affected Products

VendorProductVersions
internationalcolorconsortiumiccdev< 2.3.1.6, 2.3.1.1, 2.3.1.2, 2.3.1.3, 2.3.1.4, 2.3.1.5

References

  • https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-4f3j-q8mm-5hr6(x_refsource_CONFIRM)
  • https://github.com/InternationalColorConsortium/iccDEV/issues/672(x_refsource_MISC)
  • https://github.com/InternationalColorConsortium/iccDEV/pull/686(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-34539 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile CTiffImg::WriteLine heap-based overflow (ID 672)
→ No new info (linked only)
CVSS 3.16.2 CRITICAL
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available2.3.1.6
CWECWE-122
PublishedMar 31, 2026
Last enriched3h agov2
Trending Score49
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-34534EXP
iccDEV: HBO in CIccMpeSpectralMatrix::Describe()
Trending: 49
CRITICALCVE-2026-34535EXP
iccDEV: SEGV in CIccTagArray::Cleanup()
Trending: 49
CRITICALCVE-2026-34540EXP
iccDEV: HBO in icMemDump()
Trending: 49
HIGHCVE-2026-34533EXP
iccDEV: UB in CIccCalculatorFunc::ApplySequence()
Trending: 46
HIGHCVE-2026-34546EXP
iccDEV: UB at TiffImg.h
Trending: 46

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Mar 31, 2026
Discovered by ZDM
Mar 31, 2026
Actively Exploited
Mar 31, 2026
Patch Available
Mar 31, 2026
Updated: description, affectedVersions, severity, activelyExploited, patchAvailable
Apr 1, 2026

Version History

v2
Last enriched 3h ago
v2Tier C3h ago

Updated severity to CRITICAL, added affected versions 2.3.1.1 to 2.3.1.5, and noted that the vulnerability is actively exploited.

descriptionaffectedVersionsseverityactivelyExploitedpatchAvailable
via VulDB
v18h ago

Initial creation