High Vulnerabilities
Total Page:16
File Type:pdf, Size:1020Kb
Vulnerability Summary for the Week of June 29, 2020 The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores: • High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0 • Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9 • Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9 Entries may include additional information provided by organizations and efforts sponsored by Ug-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of Ug-CERT analysis. High Vulnerabilities CVS Source Primary Publish S Description & Patch Vendor -- Product ed Scor Info e CVE- Adobe Bridge versions 10.0.1 and 2020- earlier version have an use after free 2020- adobe -- bridge 9.3 9566 vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution . RM Adobe Bridge versions 10.0.1 and CVE- earlier version have an out-of-bounds 2020- 2020- adobe -- bridge write vulnerability. Successful 9.3 9564 06-26 exploitation could lead to arbitrary code CONFI execution . RM CVE- Adobe Bridge versions 10.0.1 and 2020- earlier version have a heap overflow 2020- adobe -- bridge 9.3 9562 vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution. RM Adobe Bridge versions 10.0.1 and CVE- 2020- adobe -- bridge earlier version have an out-of-bounds 9.3 2020- 06-26 write vulnerability. Successful 9569 CVS Source Primary Publish S Description & Patch Vendor -- Product ed Scor Info e exploitation could lead to arbitrary code CONFI execution . RM Adobe Bridge versions 10.0.1 and CVE- earlier version have a memory 2020- 2020- adobe -- bridge corruption vulnerability. Successful 9.3 9568 06-26 exploitation could lead to arbitrary code CONFI execution . RM Adobe Bridge versions 10.0.1 and CVE- earlier version have an out-of-bounds 2020- 2020- adobe -- bridge write vulnerability. Successful 9.3 9565 06-26 exploitation could lead to arbitrary code CONFI execution . RM CVE- Adobe Bridge versions 10.0.1 and 2020- earlier version have an use after free 2020- adobe -- bridge 9.3 9567 vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution . RM CVE- Adobe Bridge versions 10.0.1 and 2020- earlier version have a heap overflow 2020- adobe -- bridge 9.3 9563 vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution. RM Adobe Bridge versions 10.0.1 and CVE- earlier version have an out-of-bounds 2020- 2020- adobe -- bridge write vulnerability. Successful 9.3 9559 06-26 exploitation could lead to arbitrary code CONFI execution . RM Adobe Bridge versions 10.0.1 and CVE- earlier version have an out-of-bounds 2020- 2020- adobe -- bridge write vulnerability. Successful 9.3 9560 06-26 exploitation could lead to arbitrary code CONFI execution . RM CVS Source Primary Publish S Description & Patch Vendor -- Product ed Scor Info e Adobe Bridge versions 10.0.1 and CVE- earlier version have an out-of-bounds 2020- 2020- adobe -- bridge write vulnerability. Successful 9.3 9556 06-26 exploitation could lead to arbitrary code CONFI execution . RM Adobe Bridge versions 10.0.1 and CVE- earlier version have a stack-based buffer 2020- 2020- adobe -- bridge overflow vulnerability. Successful 9.3 9555 06-26 exploitation could lead to arbitrary code CONFI execution. RM Adobe Bridge versions 10.0.1 and CVE- earlier version have an out-of-bounds 2020- 2020- adobe -- bridge write vulnerability. Successful 9.3 9554 06-26 exploitation could lead to arbitrary code CONFI execution . RM Adobe Bridge versions 10.0.1 and CVE- earlier version have an out-of-bounds 2020- 2020- adobe -- bridge write vulnerability. Successful 9.3 9561 06-26 exploitation could lead to arbitrary code CONFI execution . RM CVE- Adobe Character Animator versions 3.2 2020- adobe -- and earlier have a buffer overflow 2020- 9.3 9586 character_animator vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution. RM Adobe DNG Software Development Kit CVE- adobe -- (SDK) 1.5 and earlier versions have a 2020- 2020- dng_software_developm heap overflow vulnerability. Successful 9.3 9589 06-26 ent_kit exploitation could lead to arbitrary code CONFI execution. RM adobe -- Adobe DNG Software Development Kit CVE- 2020- dng_software_developm (SDK) 1.5 and earlier versions have a 9.3 2020- 06-26 ent_kit heap overflow vulnerability. Successful 9590 CVS Source Primary Publish S Description & Patch Vendor -- Product ed Scor Info e exploitation could lead to arbitrary code CONFI execution. RM Adobe DNG Software Development Kit CVE- adobe -- (SDK) 1.5 and earlier versions have a 2020- 2020- dng_software_developm heap overflow vulnerability. Successful 9.3 9620 06-26 ent_kit exploitation could lead to arbitrary code CONFI execution. RM Adobe DNG Software Development Kit CVE- adobe -- (SDK) 1.5 and earlier versions have a 2020- 2020- dng_software_developm heap overflow vulnerability. Successful 9.3 9621 06-26 ent_kit exploitation could lead to arbitrary code CONFI execution. RM CVE- Adobe Illustrator versions 24.0.2 and 2020- earlier have a memory corruption 2020- adobe -- illustrator 9.3 9573 vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution. RM CVE- Adobe Illustrator versions 24.0.2 and 2020- earlier have a memory corruption 2020- adobe -- illustrator 9.3 9574 vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution . RM CVE- Adobe Illustrator versions 24.0.2 and 2020- earlier have a memory corruption 2020- adobe -- illustrator 9.3 9572 vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution. RM CVE- Adobe Illustrator versions 24.0.2 and 2020- earlier have a memory corruption 2020- adobe -- illustrator 9.3 9571 vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution. RM CVS Source Primary Publish S Description & Patch Vendor -- Product ed Scor Info e CVE- Adobe Illustrator versions 24.0.2 and 2020- earlier have a memory corruption 2020- adobe -- illustrator 9.3 9570 vulnerability. Successful exploitation 06-26 CONFI could lead to arbitrary code execution . RM Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 7.5 9585 a defense-in-depth security mitigation 06-26 CONFI vulnerability. Successful exploitation RM could lead to arbitrary code execution. Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 7.5 9576 a command injection vulnerability. 06-26 CONFI Successful exploitation could lead to RM arbitrary code execution. Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 7.5 9582 a command injection vulnerability. 06-26 CONFI Successful exploitation could lead to RM arbitrary code execution. Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 7.5 9583 a command injection vulnerability. 06-26 CONFI Successful exploitation could lead to RM arbitrary code execution. Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 7.5 9580 a security mitigation bypass 06-26 CONFI vulnerability. Successful exploitation RM could lead to arbitrary code execution. CVS Source Primary Publish S Description & Patch Vendor -- Product ed Scor Info e Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 10 9631 a security mitigation bypass 06-26 CONFI vulnerability. Successful exploitation RM could lead to arbitrary code execution. Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 7.5 9578 a command injection vulnerability. 06-26 CONFI Successful exploitation could lead to RM arbitrary code execution. Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 7.5 9630 a business logic error vulnerability. 06-26 CONFI Successful exploitation could lead to RM privilege escalation. Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 10 9632 a security mitigation bypass 06-26 CONFI vulnerability. Successful exploitation RM could lead to arbitrary code execution. Magento versions 2.3.4 and earlier, CVE- 2.2.11 and earlier (see note), 1.14.4.4 2020- and earlier, and 1.9.4.4 and earlier have 2020- adobe -- magento 7.5 9579 a security mitigation bypass 06-26 CONFI vulnerability.