CVE-2023-44362 – ZDI-CAN-21791: Adobe Prelude MP4 File Uninitialized Variable Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-44362
Adobe Prelude versions 22.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Las versiones 22.6 y anteriores de Adobe Prelude se ven afectadas por una vulnerabilidad de acceso a puntero no inicializado que podría provocar la divulgación de memoria confidencial. Un atacante podría aprovechar esta vulnerabilidad para evitar mitigaciones como ASLR. • https://helpx.adobe.com/security/products/prelude/apsb23-67.html • CWE-824: Access of Uninitialized Pointer •
CVE-2021-43754 – Adobe Prelude Corruption could lead to Arbitrary code execution
https://notcve.org/view.php?id=CVE-2021-43754
Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. Adobe Prelude versión 22.1.1 (y anteriores) está afectada por una vulnerabilidad de corrupción de memoria debido a un manejo no segura de un archivo malicioso, resultando potencialmente en una ejecución de código arbitrario en el contexto del usuario actual. Es requerida la interacción del usuario para explotar esta vulnerabilidad • https://helpx.adobe.com/security/products/prelude/apsb21-114.html • CWE-787: Out-of-bounds Write •
CVE-2021-44696 – Adobe Prelude JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-44696
Adobe Prelude version 22.1.1 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious JPEG file. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Prelude. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG images. • https://helpx.adobe.com/security/products/prelude/apsb21-114.html • CWE-125: Out-of-bounds Read •
CVE-2021-42738 – Adobe Prelude MXF File Parsing Memory Corruption Arbitrary Code Execution
https://notcve.org/view.php?id=CVE-2021-42738
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability. Adobe Prelude versión 10.1 (y anteriores), está afectada por una vulnerabilidad de corrupción de memoria debido a un manejo no seguro de un archivo MXF malicioso, resultando potencialmente en una ejecución de código arbitrario en el contexto del usuario actual. Se requiere la interacción de usuario, ya que la víctima debe abrir un archivo especialmente diseñado para aprovechar esta vulnerabilidad • https://helpx.adobe.com/security/products/prelude/apsb21-96.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-788: Access of Memory Location After End of Buffer •
CVE-2021-42737 – Adobe Prelude WAV File Parsing Memory Corruption Arbitrary Code Execution
https://notcve.org/view.php?id=CVE-2021-42737
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability. Adobe Prelude versión 10.1 (y anteriores), está afectada por una vulnerabilidad de corrupción de memoria debido a un manejo no seguro de un archivo WAV malicioso, resultando potencialmente en una ejecución de código arbitrario en el contexto del usuario actual. Es requerida una interacción de usuario, ya que la víctima debe abrir un archivo especialmente diseñado para explotar esta vulnerabilidad • https://helpx.adobe.com/security/products/prelude/apsb21-96.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-788: Access of Memory Location After End of Buffer •