Null Pointer Dereference and Undefined Behavior in iccDEV Tools
CVE-2026-24404
7.1HIGH
What is CVE-2026-24404?
The iccDEV library contains a vulnerability that arises from unsafe handling of user input in ICC profile data. This flaw, found in versions 2.3.1.1 and earlier, can lead to null pointer dereferences or undefined behavior, which an attacker might exploit for various malicious purposes. Exploitation may lead to denial of service (DoS), data manipulation, logic bypass within the application, or even unauthorized code execution. This issue has been resolved in version 2.3.1.2, ensuring improved security for users.
Affected Version(s)
iccDEV < 2.3.1.2
