Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-21549

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

PUBLISHED
Vendor
Unisoc (Shanghai) Technologies Co., Ltd.
Product
T8100/T9100/T8200/T8300
Provider severity
HIGH
Conflicts
1

CVE-2026-21548

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.

PUBLISHED
Vendor
Unisoc (Shanghai) Technologies Co., Ltd.
Product
T8100/T9100/T8200/T8300
Provider severity
HIGH
Conflicts
1

CVE-2026-2154

A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impacted is an unknown function of the file /registration.php of the component Patient Registration Module. The manipulation of the argument First Name leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

PUBLISHED
Vendor
Patrick Mvuma, SourceCodester
Product
Patients Waiting Area Queue Management System, Patients Waiting Area Queue Management System
Provider severity
MEDIUM
Conflicts
3

CVE-2026-21537

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Defender for Endpoint for Linux
Provider severity
HIGH
Conflicts
0

CVE-2026-21536

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

PUBLISHED
Vendor
Microsoft
Product
Microsoft Devices Pricing Program
Provider severity
CRITICAL
Conflicts
0

CVE-2026-21535

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Teams
Provider severity
HIGH
Conflicts
0

CVE-2026-21533

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2012, Windows 11 Version 26H1, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 22H3, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012 R2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-21532

Azure Function Information Disclosure Vulnerability

PUBLISHED
Vendor
Microsoft
Product
Azure Functions
Provider severity
HIGH
Conflicts
0

CVE-2026-21531

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure AI Language Authoring
Provider severity
CRITICAL
Conflicts
0

CVE-2026-21530

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Microsoft 365 Apps for Enterprise, Windows Server 2022, Microsoft Office 2016, Microsoft Office LTSC 2024, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Microsoft Office LTSC 2021, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2012, Microsoft Office 2019, Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2016, Windows 11 version 23H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2153

A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
mwielgoszewski
Product
doorman
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21529

Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure HDInsight
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21528

Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure IoT Explorer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21527

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14
Provider severity
MEDIUM
Conflicts
2

CVE-2026-21525

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2025, Windows Server 2012 R2, Windows 11 Version 26H1, Windows Server 2019, Windows 10 Version 22H2, Windows Server 2016, Windows 11 Version 24H2, Windows Server 2012, Windows 11 version 22H3, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2019 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21524

Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Data Explorer
Provider severity
HIGH
Conflicts
0

CVE-2026-21523

Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Visual Studio Code, Microsoft Visual Studio Code CoPilot Chat Extension
Provider severity
HIGH
Conflicts
1

CVE-2026-21522

Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft ACI Confidential Containers
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21521

Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Word Copilot
Provider severity
HIGH
Conflicts
0

CVE-2026-21520

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector

PUBLISHED
Vendor
Microsoft
Product
Microsoft Copilot Studio
Provider severity
HIGH
Conflicts
0

CVE-2026-2152

A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/ submask/ gw results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-615
Provider severity
HIGH
Conflicts
2

CVE-2026-21519

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 11 Version 23H2, Windows 11 Version 26H1, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2, Windows 11 version 22H3, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2019, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-21518

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Visual Studio Code, Microsoft Visual Studio Code CoPilot Chat Extension
Provider severity
HIGH
Conflicts
1

CVE-2026-21517

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows App for Mac
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21516

Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
GitHub Copilot Plugin for JetBrains IDEs
Provider severity
HIGH
Conflicts
0

CVE-2026-21515

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure IOT Central
Provider severity
CRITICAL
Conflicts
0

CVE-2026-21514

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-21513

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 23H2, Windows 10 Version 1809, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows Server 2016, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 11 version 22H3, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2012, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-21512

Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure DevOps Server 2022
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21511

Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Word 2016, Microsoft Office LTSC 2021, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC for Mac 2021, Microsoft SharePoint Server 2019, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-21510

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2019, Windows Server 2025, Windows Server 2012, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2012 R2, Windows 11 version 26H1, Windows 10 Version 1809, Windows 11 Version 26H1, Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 22H3
Provider severity
HIGH
Conflicts
1

CVE-2026-2151

A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr  leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-615
Provider severity
HIGH
Conflicts
2

CVE-2026-21509

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-21508

Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows Server 2019, Windows 11 Version 23H2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2012, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2025, Windows Server 2012 R2, Windows 10 Version 1809, Windows 11 version 22H3, Windows 11 Version 26H1, Windows 10 Version 1607, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-21507

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have an infinite loop in the IccProfile.cpp function, CalcProfileID. This issue is fixed in version 2.3.1.1.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
HIGH
Conflicts
0

CVE-2026-21506

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to Null pointer dereference in CIccProfileXml::ParseBasic(), leading to denial of service. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21505

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV has undefined behavior due to an invalid enum value. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21504

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap buffer overflow in the ToneMap parser. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21503

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV has undefined behavior due to a null pointer passed to memcpy() in CIccTagSparseMatrixArray. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21502

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML tag parser. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21501

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the calculator parser. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21500

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the XML calculator macro expansion. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2150

A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /checkin.php. This manipulation of the argument patient_id causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
Patrick Mvuma, SourceCodester
Product
Patients Waiting Area Queue Management System, Patients Waiting Area Queue Management System
Provider severity
MEDIUM
Conflicts
3

CVE-2026-21499

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML parser. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21498

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML calculator parser. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21497

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via an unknown tag parser. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21496

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the signature parser. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21495

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to division by zero in the TIFF Image Reader. This issue has been patched in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21494

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It results in heap buffer overflow in `CIccTagLut8::Validate()`. Version 2.3.1.2 contains a patch. No known workarounds are available.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21493

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
MEDIUM
Conflicts
1