CVE-2020-3740Out-of-bounds Write in Adobe Framemaker

Severity
9.8CRITICALNVD
EPSS
8.0%
top 7.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateMay 24

Description

Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDadobe/framemaker2019.0.4
CVEListV5adobe/adobe_framemaker2019.0.4 and below versions

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xhmj-2p35-gj29: Adobe Framemaker versions 20192022-05-24
CVEList
CVE-2020-3740: Adobe Framemaker versions 20192020-02-13

📋Vendor Advisories

2
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Comp Management and Life Cycle Management (RSA BSAFE Crypto-J) — CVE-2019-37402020-10-15
Oracle
Oracle Oracle Retail Applications Risk Matrix: SIM Integration (BSAFE Crypto-J) — CVE-2019-37402020-07-15

💬Community

5
Bugzilla
CVE-2020-6575 chromium-browser: Race in Mojo2020-09-08
Bugzilla
CVE-2020-6573 chromium-browser: Use after free in video2020-09-08
Bugzilla
CVE-2020-6576 chromium-browser: Use after free in offscreen canvas2020-09-08
Bugzilla
CVE-2020-15959 chromium-browser: Insufficient policy enforcement in networking2020-09-08
Bugzilla
CVE-2020-6574 chromium-browser: Insufficient policy enforcement in installer2020-09-08
CVE-2020-3740 — Out-of-bounds Write in Adobe Framemaker | cvebase