CVE-2026-30984: iccDEV has a heap out-of-bounds read in CIccCalculatorFunc::ApplySequence()
Published Mar 10, 2026
·Updated
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap out-of-bounds read in CIccCalculatorFunc::ApplySequence() causing an application crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
2 affected components
iccDEV iccDEV<2.3.1.5
Color iccDEV<2.3.1.5
Remediation
Event History
Mar 10, 2026
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 6, 58175
Event
via FIRST·04:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-30984?
CVE-2026-30984 is classified as a vulnerability that can cause an application crash due to a heap out-of-bounds read.
2
How do I fix CVE-2026-30984?
To fix CVE-2026-30984, you should upgrade to iccDEV version 2.3.1.5 or later.
3
What impact does CVE-2026-30984 have on applications?
The impact of CVE-2026-30984 can result in application crashes when exploiting the heap out-of-bounds read.
4
Which versions of iccDEV are affected by CVE-2026-30984?
CVE-2026-30984 affects iccDEV versions below 2.3.1.5.
5
Is CVE-2026-30984 publicly known?
Yes, CVE-2026-30984 is a publicly disclosed vulnerability associated with the iccDEV software.