VDB
CVE-2021-40732
CVE-2021-40732
PUBLISHED
CVSS 6.099999904632568 MEDIUM
Adobe has released updates for XMP Toolkit SDK. These updates resolve an important vulnerability. Successful exploitation could lead to arbitrary file system read in the context of the current user. Vulnerability: NULL Pointer Dereference (CWE-476) Impact: Application denial-of-service Severity: Important CVSS: 6.1 CWE: CWE-476
EPSS 2.45% · 83.2th percentile
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
EPSS Score
2.45%
83.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Adobe XMP-Toolkit-SDK | 2021.07, 2021.07 |
Timeline
- Sep 14, 2021 CVE Published
- Oct 14, 2021 EPSS Score
- Oct 21, 2021 EPSS Score
- Dec 10, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 2, 2022 EPSS Score
- May 28, 2022 EPSS Score
- Jul 25, 2022 EPSS Score
- Sep 20, 2022 EPSS Score
- Jan 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score