7.8
CVE-2026-48389
- EPSS 0.19%
- Veröffentlicht 20.07.2026 18:14:22
- Zuletzt bearbeitet 11.08.2026 18:57:22
- CVE-Watchlists
- Unerledigt
DNG SDK | Stack-based Buffer Overflow (CWE-121)
DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Dng Software Development Kit Version < 1.7.1.2611
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.085 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Adobe | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
https://helpx.adobe.com/security/products/dng-sdk/apsb26-67.html