CVE-2021-40716
published 2021-09-29CVE-2021-40716: XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An…
PriorityP426medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
2.17%
80.3th percentile
XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | xmp_toolkit | unspecified – 2021.07 | — |
| adobe | xmp_toolkit_software_development_kit | <= 2021.07 | — |
| debian | debian_linux | — | — |
| debian | exempi | < exempi 2.6.0-1 (bookworm) | exempi 2.6.0-1 (bookworm) |
| exempi_project | exempi | >= 0 < 2.5.2-1+deb11u1 | 2.5.2-1+deb11u1 |
| exempi_project | exempi | >= 0 < 2.6.0-1 | 2.6.0-1 |
| exempi_project | exempi | >= 0 < 2.6.0-1 | 2.6.0-1 |
| exempi_project | exempi | >= 0 < 2.6.0-1 | 2.6.0-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Exempi vulnerabilities
vendor_ubuntu·2022-06-16
CVE-2021-36048 Exempi vulnerabilities
Title: Exempi vulnerabilities
Summary: Several security issues were fixed in Exempi.
It was discovered that Exempi incorrectly handled certain media files. If a
user or automated system were tricked into opening a specially crafted
file, a remote attacker could cause Exempi to stop responding or crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-40716: exempi - XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds ...
vendor_debian·2021·CVSS 5.5
CVE-2021-40716 [MEDIUM] CVE-2021-40716: exempi - XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds ...
XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Scope: local
bookworm: resolved (fixed in 2.6.0-1)
bullseye: resolved (fixed in 2.5.2-1+deb11u1)
forky: resolved (fixed in 2.6.0-1)
sid: resolved (fixed in 2.6.0-1)
trixie: resolved (fixed in 2.6.0-1)
GHSA
GHSA-h9rm-h58w-49mj: XMP Toolkit SDK versions 2021
ghsa_unreviewed·2022-05-24
CVE-2021-40716 [MEDIUM] CWE-125 GHSA-h9rm-h58w-49mj: XMP Toolkit SDK versions 2021
XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
OSV
CVE-2021-40716: XMP Toolkit SDK versions 2021
osv·2021-09-29·CVSS 5.5
CVE-2021-40716 [MEDIUM] CVE-2021-40716: XMP Toolkit SDK versions 2021
XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://helpx.adobe.com/security/products/xmpcore/apsb21-85.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00032.htmlhttps://helpx.adobe.com/security/products/xmpcore/apsb21-85.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2025/08/msg00003.html
2021-09-29
Published