Argyllcms is a specialized color-management toolkit used in professional imaging workflows, with a narrow but technically sophisticated product scope centered on the cms library and related utilities. The observed weakness class centers on improper memory-buffer restrictions, reflecting the low-level data processing and color-space transformation logic inherent to the software. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Argyllcms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1616HIGH Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause a denial of service (crash) or ex | Jun 21, 2012 | 9.3 | 31 | NO | NO |
CVE-2009-0792HIGH Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management Sys | Apr 14, 2009 | 9.3 | 30 | NO | NO |
CVE-2009-0583HIGH Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management Sys | Mar 23, 2009 | 9.3 | 27 | NO | NO |
CVE-2012-4405MEDIUM Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management | Sep 18, 2012 | 6.8 | 26 | NO | NO |
CVE-2009-0584HIGH icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, a | Mar 23, 2009 | 9.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Argyllcms.
Media articles that mention a CVE ID that affects a product developed by Argyllcms — matched by CVE ID, not by vendor name.