| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35033 | Hig | 0.51 | 7.8 | 0.00 | Nov 23, 2021 | A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable… | ||
| CVE-2021-43775 | Hig | 0.49 | 8.6 | 0.02 | Nov 23, 2021 | Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute… | ||
| CVE-2021-41281 | Hig | 0.42 | 7.5 | 0.02 | Nov 23, 2021 | Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the… | ||
| CVE-2021-38891 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508. | ||
| CVE-2021-38890 | Hig | 0.49 | 7.5 | 0.02 | Nov 23, 2021 | IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507. | ||
| CVE-2021-36314 | Hig | 0.46 | 7.1 | 0.01 | Nov 23, 2021 | Dell EMC CloudLink 7.1 and all prior versions contain an Arbitrary File Creation Vulnerability. A remote unauthenticated attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary files on the end user system. | ||
| CVE-2021-36299 | Hig | 0.49 | 7.1 | 0.30 | Nov 23, 2021 | Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by… | ||
| CVE-2021-24892 | Hig | 0.00 | 8.8 | 0.02 | Nov 23, 2021 | Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To… | ||
| CVE-2021-24877 | Hig | 0.47 | 7.2 | 0.01 | Nov 23, 2021 | The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed | ||
| CVE-2021-24644 | Hig | 0.49 | 7.5 | 0.05 | Nov 23, 2021 | The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue | ||
| CVE-2021-24641 | Hig | 0.53 | 8.1 | 0.01 | Nov 23, 2021 | The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion | ||
| CVE-2021-21561 | Hig | 0.51 | 7.8 | 0.00 | Nov 23, 2021 | Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files. | ||
| CVE-2021-43019 | Hig | 0.51 | 7.8 | 0.02 | Nov 23, 2021 | Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of… | ||
| CVE-2021-37102 | Hig | 0.57 | 8.8 | 0.01 | Nov 23, 2021 | There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user… | ||
| CVE-2021-37035 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly. | ||
| CVE-2021-37034 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is an Unstandardized field names in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-37033 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2021-37031 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly. | ||
| CVE-2021-37030 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2021-37026 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37025 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37024 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37019 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37018 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37017 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37015 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37012 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37010 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected. | ||
| CVE-2021-37009 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Configuration vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected. | ||
| CVE-2021-37008 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37007 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37006 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected. | ||
| CVE-2021-37005 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37004 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-37003 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | ||
| CVE-2021-35052 | Hig | 0.51 | 7.8 | 0.00 | Nov 23, 2021 | A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High. | ||
| CVE-2021-39976 | Hig | 0.51 | 7.8 | 0.00 | Nov 23, 2021 | There is a privilege escalation vulnerability in CloudEngine 5800 V200R020C00SPC600. Due to lack of privilege restrictions, an authenticated local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a… | ||
| CVE-2021-20601 | — | Hig | 0.49 | 7.5 | 0.02 | Nov 23, 2021 | Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versions, GOT SIMPLE series GS21 model all versions, and GT SoftGOT2000 all versions… | |
| CVE-2021-44150 | — | Hig | 0.49 | 7.5 | 0.01 | Nov 22, 2021 | The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content. | |
| CVE-2021-42707 | Hig | 0.51 | 7.8 | 0.01 | Nov 22, 2021 | PLC Editor Versions 1.3.8 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code. | ||
| CVE-2021-42705 | Hig | 0.51 | 7.8 | 0.01 | Nov 22, 2021 | PLC Editor Versions 1.3.8 and prior is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code. | ||
| CVE-2021-38448 | Hig | 0.49 | 7.5 | 0.00 | Nov 22, 2021 | The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software. | ||
| CVE-2021-43559 | — | Hig | 0.50 | 8.8 | 0.01 | Nov 22, 2021 | A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk. | |
| CVE-2021-43015 | Hig | 0.51 | 7.8 | 0.02 | Nov 22, 2021 | Adobe InCopy version 16.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious GIF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must… | ||
| CVE-2021-42738 | Hig | 0.51 | 7.8 | 0.02 | Nov 22, 2021 | Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must… | ||
| CVE-2021-42737 | Hig | 0.51 | 7.8 | 0.02 | Nov 22, 2021 | Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must… | ||
| CVE-2021-42727 | Hig | 0.54 | 7.8 | 0.39 | Nov 22, 2021 | Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a… | ||
| CVE-2021-40775 | Hig | 0.51 | 7.8 | 0.02 | Nov 22, 2021 | Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must… | ||
| CVE-2021-40772 | Hig | 0.51 | 7.8 | 0.02 | Nov 22, 2021 | Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must… | ||
| CVE-2021-40771 | Hig | 0.51 | 7.8 | 0.02 | Nov 22, 2021 | Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must… |
- risk 0.51cvss 7.8epss 0.00
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable…
- risk 0.49cvss 8.6epss 0.02
Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute…
- risk 0.42cvss 7.5epss 0.02
Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the…
- risk 0.49cvss 7.5epss 0.01
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.
- risk 0.49cvss 7.5epss 0.02
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.
- risk 0.46cvss 7.1epss 0.01
Dell EMC CloudLink 7.1 and all prior versions contain an Arbitrary File Creation Vulnerability. A remote unauthenticated attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary files on the end user system.
- risk 0.49cvss 7.1epss 0.30
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by…
- risk 0.00cvss 8.8epss 0.02
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To…
- risk 0.47cvss 7.2epss 0.01
The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed
- risk 0.49cvss 7.5epss 0.05
The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue
- risk 0.53cvss 8.1epss 0.01
The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion
- risk 0.51cvss 7.8epss 0.00
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files.
- risk 0.51cvss 7.8epss 0.02
Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of…
- risk 0.57cvss 8.8epss 0.01
There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user…
- risk 0.49cvss 7.5epss 0.01
There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.
- risk 0.49cvss 7.5epss 0.01
There is an Unstandardized field names in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- risk 0.49cvss 7.5epss 0.01
There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.
- risk 0.49cvss 7.5epss 0.01
There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
- risk 0.49cvss 7.5epss 0.01
There is a Configuration vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
- risk 0.51cvss 7.8epss 0.00
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
- risk 0.51cvss 7.8epss 0.00
There is a privilege escalation vulnerability in CloudEngine 5800 V200R020C00SPC600. Due to lack of privilege restrictions, an authenticated local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a…
- risk 0.49cvss 7.5epss 0.02
Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versions, GOT SIMPLE series GS21 model all versions, and GT SoftGOT2000 all versions…
- risk 0.49cvss 7.5epss 0.01
The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.
- risk 0.51cvss 7.8epss 0.01
PLC Editor Versions 1.3.8 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
PLC Editor Versions 1.3.8 and prior is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.
- risk 0.49cvss 7.5epss 0.00
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.
- risk 0.50cvss 8.8epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
- risk 0.51cvss 7.8epss 0.02
Adobe InCopy version 16.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious GIF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…
- risk 0.51cvss 7.8epss 0.02
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…
- risk 0.51cvss 7.8epss 0.02
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…
- risk 0.54cvss 7.8epss 0.39
Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.02
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…
- risk 0.51cvss 7.8epss 0.02
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…
- risk 0.51cvss 7.8epss 0.02
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…