VDB

CVE-2021-40732

CVE-2021-40732 PUBLISHED CVSS 6.099999904632568 MEDIUM

Adobe has released updates for XMP Toolkit SDK. These updates resolve an  important vulnerability. Successful exploitation could lead to arbitrary file system read  in the context of the current user. Vulnerability: NULL Pointer Dereference (CWE-476) Impact: Application denial-of-service Severity: Important CVSS: 6.1 CWE: CWE-476

EPSS 2.45% · 83.2th percentile

Risk Scores

CVSS 3.1
6.099999904632568
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
EPSS Score
2.45%
83.2th percentile

Affected Products

VendorProductVersions
AdobeAdobe XMP-Toolkit-SDK2021.07, 2021.07

Timeline

  • Sep 14, 2021 CVE Published
  • Oct 14, 2021 EPSS Score
  • Oct 21, 2021 EPSS Score
  • Dec 10, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 2, 2022 EPSS Score
  • May 28, 2022 EPSS Score
  • Jul 25, 2022 EPSS Score
  • Sep 20, 2022 EPSS Score
  • Jan 11, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›