Stack Buffer Overflow Vulnerability in ICC Color Management Tool by International Color Consortium
CVE-2026-30987

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-30987?

A stack buffer overflow vulnerability exists in the CIccTagNum<>::GetValues() function of the iccDEV library, impacting versions prior to 2.3.1.5. This flaw can lead to stack memory corruption or crashes, potentially allowing an attacker to disrupt service or execute arbitrary code. Users are encouraged to upgrade to version 2.3.1.5 or later to mitigate this risk.

Affected Version(s)

iccDEV < 2.3.1.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.