Null Pointer Dereference and Undefined Behavior in iccDEV Tools
CVE-2026-24404

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 January 2026

What is CVE-2026-24404?

The iccDEV library contains a vulnerability that arises from unsafe handling of user input in ICC profile data. This flaw, found in versions 2.3.1.1 and earlier, can lead to null pointer dereferences or undefined behavior, which an attacker might exploit for various malicious purposes. Exploitation may lead to denial of service (DoS), data manipulation, logic bypass within the application, or even unauthorized code execution. This issue has been resolved in version 2.3.1.2, ensuring improved security for users.

Affected Version(s)

iccDEV < 2.3.1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.