Latest CVE Feed
-
9.3
HIGHCVE-2021-42727
Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in tha... Read more
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-42726
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required... Read more
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42725
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required... Read more
Affected Products : bridge- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42724
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to ... Read more
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-42723
Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted SGI file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to exec... Read more
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42722
Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute ... Read more
Affected Products : bridge- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-42721
Acrobat Bridge versions 11.1.1 and earlier are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user ... Read more
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42720
Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute ... Read more
Affected Products : bridge- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42719
Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted .jpe file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to exe... Read more
Affected Products : bridge- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-42716
An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially ... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-42715
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_imag... Read more
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42714
Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.... Read more
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42713
Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions.... Read more
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42712
Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.... Read more
Affected Products : streamer- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42711
Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a repair operation.... Read more
Affected Products : network_access_client- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42707
PLC Editor Versions 1.3.8 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.... Read more
Affected Products : plc_editor- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42706
This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer... Read more
Affected Products : webaccess_hmi_designer- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42705
PLC Editor Versions 1.3.8 and prior is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.... Read more
Affected Products : plc_editor- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-42704
Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.... Read more
Affected Products : inkscape- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-42703
This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.... Read more
Affected Products : webaccess_hmi_designer- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024