CVE-2024-43760
published 2024-09-13CVE-2024-43760: Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the…
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.33%
25.7th percentile
Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | photoshop | < 24.7.5 | 24.7.5 |
| adobe | photoshop | >= 25.0 < 25.12 | 25.12 |
| adobe | photoshop_desktop | <= 25.11 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect
ghsa·2025-08-22
CVE-2025-43760 [MEDIUM] CWE-79 Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect
Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.6, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92 allows an remote authenticated attacker to inject JavaScript into the PortalUtil.escapeRedirect
GHSA
GHSA-7882-x554-9hgx: Photoshop Desktop versions 24
ghsa_unreviewed·2024-09-13
CVE-2024-43760 [HIGH] CWE-787 GHSA-7882-x554-9hgx: Photoshop Desktop versions 24
Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-13
Published