Page 15 of 74 results (0.010 seconds)

CVSS: 9.3EPSS: 0%CPEs: 2EXPL: 0

Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. Adobe Bridge versiones 11.1 (y anteriores), está afectada por una vulnerabilidad de corrupción de memoria debido a un manejo no seguro de un archivo Bridge malicioso, resultando potencialmente en una ejecución de código arbitrario en el contexto del usuario actual. Es requerida una interacción del usuario para explotar esta vulnerabilidad This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. • https://helpx.adobe.com/security/products/bridge/apsb21-69.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-788: Access of Memory Location After End of Buffer •

CVSS: 9.3EPSS: 0%CPEs: 2EXPL: 0

Adobe Bridge version 11.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted .SGI file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Adobe Bridge versiones 11.1 (y anteriores), está afectada por una vulnerabilidad de lectura fuera de límites cuando analiza un archivo .SGI diseñado, que podría resultar en una lectura más allá del final de una estructura de memoria asignada. Un atacante podría aprovechar esta vulnerabilidad para ejecutar código en el contexto del usuario actual. • https://helpx.adobe.com/security/products/bridge/apsb21-69.html • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur. Se detectó un problema en LG Bridge antes de Abril de 2019 en Windows. Un Secuestro de DLL puede ocurrir. • https://lgsecurity.lge.com • CWE-427: Uncontrolled Search Path Element •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript. Una vulnerabilidad Cross-Site Scripting (XSS) basada en DOM en el tema Bridge en versiones anteriores a la 11.2 para WordPress permite que atacantes remotos inyecten JavaScript arbitrario. • http://bridge.qodeinteractive.com/change-log http://imgur.com/a/OT9vl https://wpvulndb.com/vulnerabilities/8892 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •