CVE-2012-1616: Argyllcms
High severity, CVSS 9.3. EPSS: 4.8% chance of exploitation in the next 30 days.
Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted ICC profile file.
Affected products
- Argyllcms Argyllcms: up to and including 1.3.7; version 0.1.0 only; version 0.2.0 only; version 0.2.1 only; version 0.2.2 only; version 0.3.0 only; …
- Color Icclib: up to and including 2.11; version 1.23 only; version 2.00 only; version 2.02 only; version 2.03 only
Published 2012-06-21. Last modified 2026-06-16.