3 results (0.008 seconds)

CVSS: 4.6EPSS: 0%CPEs: 60EXPL: 0

Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs. • http://secunia.com/advisories/18698 http://securitytracker.com/id?1015577 http://securitytracker.com/id?1015578 http://securitytracker.com/id?1015579 http://www.adobe.com/support/techdocs/332644.html http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf http://www.kb.cert.org/vuls/id/953860 http://www.osvdb.org/22908 http://www.securityfocus.com/archive/1/423587/100/0/threaded http://www.securityfocus.com/bid/16451 http://www.vupen.com/english/advisories/2006/ • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 2.1EPSS: 0%CPEs: 2EXPL: 1

VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, creates temporary log files with predictable names, which allows local users to modify arbitrary files via a symlink attack. • https://www.exploit-db.com/exploits/1185 http://secunia.com/advisories/16541 http://securitytracker.com/id?1014776 http://www.adobe.com/support/techdocs/327129.html http://www.idefense.com/application/poi/display?id=297&type=vulnerabilities http://www.securityfocus.com/bid/14638 •

CVSS: 4.6EPSS: 0%CPEs: 2EXPL: 1

VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, allows local users to load arbitrary libraries and execute arbitrary code via the -lib command line argument. • https://www.exploit-db.com/exploits/1186 http://secunia.com/advisories/16541 http://securitytracker.com/id?1014776 http://www.adobe.com/support/techdocs/327129.html http://www.idefense.com/application/poi/display?id=296&type=vulnerabilities http://www.securityfocus.com/bid/14638 •