| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41807 | Hig | 0.49 | 7.5 | 0.01 | Jan 18, 2022 | Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier. | ||
| CVE-2021-39946 | Hig | 0.57 | 8.7 | 0.01 | Jan 18, 2022 | Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis | ||
| CVE-2021-29632 | Hig | 0.49 | 7.5 | 0.01 | Jan 18, 2022 | In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures… | ||
| CVE-2020-14110 | Hig | 0.51 | 7.8 | 0.00 | Jan 18, 2022 | AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background. | ||
| CVE-2020-14107 | — | Hig | 0.49 | 7.5 | 0.01 | Jan 18, 2022 | A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN. | |
| CVE-2022-23307 | Hig | 0.61 | 8.8 | 0.52 | Jan 18, 2022 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | ||
| CVE-2022-23302 | Hig | 0.62 | 8.8 | 0.62 | Jan 18, 2022 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a… | ||
| CVE-2022-0263 | Hig | 0.44 | 7.8 | 0.01 | Jan 18, 2022 | Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7. | ||
| CVE-2022-0261 | Hig | 0.00 | 7.8 | 0.02 | Jan 18, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2021-41550 | Hig | 0.47 | 7.2 | 0.01 | Jan 18, 2022 | Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code. | ||
| CVE-2021-38696 | Hig | 0.49 | 7.5 | 0.02 | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication. | ||
| CVE-2021-38785 | Hig | 0.49 | 7.5 | 0.02 | Jan 18, 2022 | There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could use the ioctl cmd IOCTL_GET_IOMMU_ADDR to cause a system crash. | ||
| CVE-2021-38784 | Hig | 0.49 | 7.5 | 0.02 | Jan 18, 2022 | There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash. | ||
| CVE-2021-38694 | Hig | 0.49 | 7.5 | 0.01 | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection. | ||
| CVE-2021-38783 | Hig | 0.49 | 7.5 | 0.02 | Jan 18, 2022 | There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl cmd IOCTL_SET_PROC_INFO and IOCTL_COPY_PROC_INFO, which could cause a system crash or EoP. | ||
| CVE-2021-33965 | Hig | 0.57 | 8.8 | 0.03 | Jan 18, 2022 | China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote… | ||
| CVE-2021-45394 | — | Hig | 0.50 | 8.8 | 0.02 | Jan 18, 2022 | An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious tag in the converted HTML document. | |
| CVE-2021-33964 | Hig | 0.57 | 8.8 | 0.03 | Jan 18, 2022 | China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use the vulnerability to execute remote… | ||
| CVE-2022-0242 | Hig | 0.40 | 7.2 | 0.01 | Jan 17, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. | ||
| CVE-2021-38965 | Hig | 0.57 | 8.8 | 0.02 | Jan 17, 2022 | IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346. | ||
| CVE-2022-0258 | Hig | 0.50 | 8.8 | 0.02 | Jan 17, 2022 | pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command | ||
| CVE-2022-0240 | Hig | 0.00 | 7.5 | 0.01 | Jan 17, 2022 | mruby is vulnerable to NULL Pointer Dereference | ||
| CVE-2021-4164 | Hig | 0.50 | 8.8 | 0.01 | Jan 17, 2022 | calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-25036 | Hig | 0.50 | 8.8 | 0.03 | Jan 17, 2022 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could… | ||
| CVE-2022-0180 | Hig | 0.57 | 8.8 | 0.01 | Jan 17, 2022 | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page. | ||
| CVE-2021-44537 | Hig | 0.51 | 7.8 | 0.03 | Jan 15, 2022 | ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution. | ||
| CVE-2021-33828 | Hig | 0.57 | 8.8 | 0.01 | Jan 15, 2022 | The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection. | ||
| CVE-2021-33827 | Hig | 0.47 | 7.2 | 0.02 | Jan 15, 2022 | The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings. | ||
| CVE-2021-42555 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation. | ||
| CVE-2021-35969 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation. | ||
| CVE-2021-33499 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2). | ||
| CVE-2021-33498 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2). | ||
| CVE-2021-32545 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation. | ||
| CVE-2022-23095 | Hig | 0.51 | 7.8 | 0.01 | Jan 15, 2022 | Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process. | ||
| CVE-2021-44049 | Hig | 0.51 | 7.8 | 0.00 | Jan 15, 2022 | CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory. | ||
| CVE-2022-23094 | Hig | 0.49 | 7.5 | 0.03 | Jan 15, 2022 | Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6. | ||
| CVE-2021-46170 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2022 | An issue was discovered in JerryScript commit a6ab5e9. There is an Use-After-Free in lexer_compare_identifier_to_string in js-lexer.c file. | ||
| CVE-2022-22531 | Hig | 0.53 | 8.1 | 0.01 | Jan 14, 2022 | The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code, resulting in sensitive information being disclosed… | ||
| CVE-2022-22530 | Hig | 0.53 | 8.1 | 0.01 | Jan 14, 2022 | The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which could result in critical… | ||
| CVE-2022-21137 | Hig | 0.51 | 7.8 | 0.09 | Jan 14, 2022 | Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code. | ||
| CVE-2022-0130 | Hig | 0.53 | 8.1 | 0.02 | Jan 14, 2022 | Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file type in the web server… | ||
| CVE-2021-46020 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2022 | An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash. | ||
| CVE-2021-45773 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2022 | A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash. | ||
| CVE-2021-45769 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2022 | A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash. | ||
| CVE-2021-45406 | Hig | 0.57 | 8.8 | 0.02 | Jan 14, 2022 | In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password. | ||
| CVE-2021-45068 | Hig | 0.52 | 7.8 | 0.12 | Jan 14, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue… | ||
| CVE-2021-45064 | Hig | 0.52 | 7.8 | 0.12 | Jan 14, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current… | ||
| CVE-2021-45062 | Hig | 0.52 | 7.8 | 0.17 | Jan 14, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current… | ||
| CVE-2021-45061 | Hig | 0.51 | 7.8 | 0.08 | Jan 14, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue… | ||
| CVE-2021-45060 | Hig | 0.51 | 7.8 | 0.09 | Jan 14, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An… |
- risk 0.49cvss 7.5epss 0.01
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
- risk 0.57cvss 8.7epss 0.01
Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis
- risk 0.49cvss 7.5epss 0.01
In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures…
- risk 0.51cvss 7.8epss 0.00
AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.
- risk 0.49cvss 7.5epss 0.01
A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN.
- risk 0.61cvss 8.8epss 0.52
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
- risk 0.62cvss 8.8epss 0.62
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a…
- risk 0.44cvss 7.8epss 0.01
Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.47cvss 7.2epss 0.01
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
- risk 0.49cvss 7.5epss 0.02
SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.
- risk 0.49cvss 7.5epss 0.02
There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could use the ioctl cmd IOCTL_GET_IOMMU_ADDR to cause a system crash.
- risk 0.49cvss 7.5epss 0.02
There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash.
- risk 0.49cvss 7.5epss 0.01
SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.
- risk 0.49cvss 7.5epss 0.02
There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl cmd IOCTL_SET_PROC_INFO and IOCTL_COPY_PROC_INFO, which could cause a system crash or EoP.
- risk 0.57cvss 8.8epss 0.03
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote…
- risk 0.50cvss 8.8epss 0.02
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious tag in the converted HTML document.
- risk 0.57cvss 8.8epss 0.03
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use the vulnerability to execute remote…
- risk 0.40cvss 7.2epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.
- risk 0.57cvss 8.8epss 0.02
IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346.
- risk 0.50cvss 8.8epss 0.02
pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
- risk 0.00cvss 7.5epss 0.01
mruby is vulnerable to NULL Pointer Dereference
- risk 0.50cvss 8.8epss 0.01
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.50cvss 8.8epss 0.03
The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could…
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.
- risk 0.51cvss 7.8epss 0.03
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
- risk 0.57cvss 8.8epss 0.01
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
- risk 0.47cvss 7.2epss 0.02
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.
- risk 0.51cvss 7.8epss 0.01
Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.
- risk 0.51cvss 7.8epss 0.00
CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.
- risk 0.49cvss 7.5epss 0.03
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in JerryScript commit a6ab5e9. There is an Use-After-Free in lexer_compare_identifier_to_string in js-lexer.c file.
- risk 0.53cvss 8.1epss 0.01
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code, resulting in sensitive information being disclosed…
- risk 0.53cvss 8.1epss 0.01
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which could result in critical…
- risk 0.51cvss 7.8epss 0.09
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.
- risk 0.53cvss 8.1epss 0.02
Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file type in the web server…
- risk 0.49cvss 7.5epss 0.01
An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash.
- risk 0.49cvss 7.5epss 0.01
A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash.
- risk 0.49cvss 7.5epss 0.01
A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash.
- risk 0.57cvss 8.8epss 0.02
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.
- risk 0.52cvss 7.8epss 0.12
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…
- risk 0.52cvss 7.8epss 0.12
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current…
- risk 0.52cvss 7.8epss 0.17
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current…
- risk 0.51cvss 7.8epss 0.08
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…
- risk 0.51cvss 7.8epss 0.09
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An…