VYPR

Xmp Toolkit Software Development Kit

by Adobe Inc.

CVEs (28)

  • CVE-2021-42528MedMay 2, 2022
    risk 0.36cvss 5.5epss 0.02

    XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user.…

  • CVE-2021-40716MedSep 29, 2021
    risk 0.36cvss 5.5epss 0.02

    XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2021-36058MedSep 1, 2021
    risk 0.36cvss 5.5epss 0.02

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potentially resulting in application-level denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

  • CVE-2021-36056MedSep 1, 2021
    risk 0.36cvss 5.5epss 0.04

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

  • CVE-2021-36057LowSep 1, 2021
    risk 0.22cvss 3.3epss 0.01

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service…

  • CVE-2021-36054LowSep 1, 2021
    risk 0.22cvss 3.3epss 0.04

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in local application denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

  • CVE-2021-36053LowSep 1, 2021
    risk 0.22cvss 3.3epss 0.02

    XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2021-36045LowSep 1, 2021
    risk 0.22cvss 3.3epss 0.02

    XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

Page 2 of 2