Vulnerabilities > Color

DATE CVE VULNERABILITY TITLE RISK
2023-11-18 CVE-2023-48736 Out-of-bounds Read vulnerability in Color Demoiccmax 20231109
In International Color Consortium DemoIccMAX 3e7948b, CIccCLUT::Interp2d in IccTagLut.cpp in libSampleICC.a has an out-of-bounds read.
network
low complexity
color CWE-125
6.5
2023-11-05 CVE-2023-47249 Out-of-bounds Write vulnerability in Color Demoiccmax 20220621
In International Color Consortium DemoIccMAX 79ecb74, a CIccXmlArrayType:::ParseText function (for unsigned short) in IccUtilXml.cpp in libIccXML.a has an out-of-bounds read.
network
low complexity
color CWE-787
6.5
2023-10-30 CVE-2023-46866 Out-of-bounds Write vulnerability in Color Demoiccmax 20220621
In International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a attempts to access array elements at out-of-bounds indexes.
network
low complexity
color CWE-787
6.5
2023-10-30 CVE-2023-46867 NULL Pointer Dereference vulnerability in Color Demoiccmax 20220621
In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a NULL pointer dereference.
network
low complexity
color CWE-476
6.5
2023-10-23 CVE-2023-46602 Out-of-bounds Write vulnerability in Color Demoiccmax 20220621
In International Color Consortium DemoIccMAX 79ecb74, there is a stack-based buffer overflow in the icFixXml function in IccXML/IccLibXML/IccUtilXml.cpp in libIccXML.a.
network
low complexity
color CWE-787
8.8
2023-10-23 CVE-2023-46603 Out-of-bounds Read vulnerability in Color Demoiccmax 20220621
In International Color Consortium DemoIccMAX 79ecb74, there is an out-of-bounds read in the CIccPRMG::GetChroma function in IccProfLib/IccPrmg.cpp in libSampleICC.a.
network
low complexity
color CWE-125
8.8
2012-06-21 CVE-2012-1616 Resource Management Errors vulnerability in multiple products
Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted ICC profile file.
network
argyllcms color CWE-399
critical
9.3