CVE-2020-9637
published 2020-06-25CVE-2020-9637: Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
8.74%
94.5th percentile
Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_after_effects | — | — |
| adobe | after_effects | <= 17.1 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Fortinet
Multiple Critical Vulnerabilities in Adobe Illustrator and After Effects Products | FortiGuard Labs
blogs_fortinet·2020-06-17·CVSS 7.8
[HIGH] Multiple Critical Vulnerabilities in Adobe Illustrator and After Effects Products | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Multiple Critical Vulnerabilities in Adobe Illustrator and After Effects Products
By Peixue Li | June 17, 2020
FortiGuard Labs Threat Research Report
Affected platforms: Windows
Impacted parties: Users of Adobe Illustrator 2020 versions 24.1.2 and earlier, Adobe After Effects versions 17.1 and earlier
Impact: Multiple Vulnerabilities leading to Arbitrary Code Execution
Severity level: Critical
This Tuesday (June 16, 2020), Adobe released out-of-band security updates to address 18 critical vulnerabilities in multiple products. Seven of them were discovered by FortiGuard Labs researchers Honggang Ren, Kushal Arvind Shah, and Yonghui Han. These vulnerabilities were discovered in Adobe’s Illustrator and After Effects solutions.
Illustrator is a vector graph
Bugzilla
CVE-2020-36780 kernel: i2c: sprd: fix reference leak when pm_runtime_get_sync fails
bugzilla·2024-02-29·CVSS 4.7
CVE-2020-36780 [MEDIUM] CVE-2020-36780 kernel: i2c: sprd: fix reference leak when pm_runtime_get_sync fails
CVE-2020-36780 kernel: i2c: sprd: fix reference leak when pm_runtime_get_sync fails
In the Linux kernel, the following vulnerability has been resolved:
i2c: sprd: fix reference leak when pm_runtime_get_sync fails
The Linux kernel CVE team has assigned CVE-2020-36780 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024022820-CVE-2020-36780-9637@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2266945]
---
This was fixed for Fedora with the 5.12.4 stable kernel updates.
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2020-36780 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built).
2020-06-25
Published