CVE-2020-3733
published 2020-02-13CVE-2020-3733: Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.97%
89.3th percentile
Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_framemaker | — | — |
| adobe | framemaker | <= 2019.0.4 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x3wx-m9w8-5wx6: Adobe Framemaker versions 2019
ghsa_unreviewed·2022-05-24
CVE-2020-3733 [MEDIUM] GHSA-x3wx-m9w8-5wx6: Adobe Framemaker versions 2019
Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.
OSV
python3.7, python3.8 vulnerabilities
osv·2021-12-17·CVSS 6.5
CVE-2020-8492 python3.7, python3.8 vulnerabilities
python3.7, python3.8 vulnerabilities
It was discovered that the urllib.request.AbstractBasicAuthHandler class
in Python contains regex allowing for catastrophic backtracking. Specially
crafted traffic from a malicious HTTP server could cause a regular expression
denial of service (ReDoS) condition for a client.
(CVE-2020-8492)
It was discovered that the urllib.request.AbstractBasicAuthHandler class
in Python contains regex with a quadratic worst-case time complexity.
Specially crafted traffic from a malicious HTTP server could cause a regular
expression denial of service (ReDoS) condition for a client.
(CVE-2021-3733)
It was discovered that the Python urllib http client could enter into an infinite
loop when incorrectly handling certain server responses (100 Continue response).
Speciall
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-13
Published