CVE-2016-7885
published 2016-12-15CVE-2016-7885: Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.
PriorityP341high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
3.45%
87.7th percentile
Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | experience_manager | <= 6.2.0 | — |
| artifex | jbig2dec | >= 0 < 0.11+20120125-1ubuntu1.1 | 0.11+20120125-1ubuntu1.1 |
| artifex | jbig2dec | >= 0 < 0.12+20150918-1ubuntu0.1 | 0.12+20150918-1ubuntu0.1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqfx-pf4p-4w43: Adobe Experience Manager versions 6
ghsa_unreviewed·2022-05-17
CVE-2016-7885 [HIGH] CWE-352 GHSA-fqfx-pf4p-4w43: Adobe Experience Manager versions 6
Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.
OSV
jbig2dec vulnerabilities
osv·2017-05-24·CVSS 5.5
CVE-2016-9601 jbig2dec vulnerabilities
jbig2dec vulnerabilities
Bingchang Liu discovered that jbig2dec incorrectly handled memory when
decoding malformed image files. If a user or automated system were tricked
into processing a specially crafted JBIG2 image file, a remote attacker
could cause jbig2dec to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only applied to Ubuntu 14.04
LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9601)
It was discovered that jbig2dec incorrectly handled memory when decoding
malformed image files. If a user or automated system were tricked into
processing a specially crafted JBIG2 image file, a remote attacker could
cause jbig2dec to crash, resulting in a denial of service, or possibly
disclose sensitive information. (CVE-2017-7885)
Jiaqi Peng discovered
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/94876http://www.securitytracker.com/id/1037464https://helpx.adobe.com/security/products/experience-manager/apsb16-42.htmlhttp://www.securityfocus.com/bid/94876http://www.securitytracker.com/id/1037464https://helpx.adobe.com/security/products/experience-manager/apsb16-42.html
2016-12-15
Published