Color's vulnerability footprint concentrates in a small set of image-processing and color-management libraries and tools, including ICC development utilities and demonstration applications, that serve specialized technical and creative workflows. Despite the narrow product scope, these components operate in a foundational role within imaging pipelines and color-space conversion chains, giving their security posture relevance across dependent applications and workflows. The recurring weakness classes—improper input validation, out-of-bounds writes and reads, heap-based buffer overflows, and NULL pointer dereferences—reflect the memory-safety and parsing demands inherent to binary image-format handling and color-profile interpretation. Defenders integrating these libraries into downstream products should prioritize input sanitization and memory-safety review during intake; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Color over time
Signals from CVEs in this vendor scope (112 CVEs).
112 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24412HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have aHeap Buffer Overflow vulnerabil | Jan 24, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-21679CRITICAL iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vul | Jan 7, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-21675CRITICAL iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free vulnerability in the CIccXform::Creat | Jan 6, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-24409HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior and Null Poin | Jan 24, 2026 | 8.8 | 31 | NO | NO |
CVE-2012-1616HIGH Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause a denial of service (crash) or ex | Jun 21, 2012 | 9.3 | 31 | NO | NO |
CVE-2026-24406HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buffer Overflow vulnerabi | Jan 24, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-22255HIGH iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versio | Jan 8, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-24411HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior in CIccTagXml | Jan 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-24410HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior and Null Poin | Jan 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-24407HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior in icSigCalcO | Jan 24, 2026 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (112 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Color.
Media articles that mention a CVE ID that affects a product developed by Color — matched by CVE ID, not by vendor name.