HIGH
DNG SDK | Heap-based Buffer Overflow (CWE-122)
Published Dec 9, 2025
7.1
HIGHCVSS 3.1
EPSS 0.20%
Description
DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected products
-
Affected
- ≥ 0, ≤ 1.7.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-202259 Advisory
- https://helpx.adobe.com/security/products/dng-sdk/apsb25-118.html vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-202259 | Advisory | |
| https://helpx.adobe.com/security/products/dng-sdk/apsb25-118.html | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Dec 9, 2025
Updated Dec 9, 2025
Reserved Nov 11, 2025
Link CVE-2025-64784
CISA Vulnrichment
Updated Dec 9, 2025
Red Hat
No data
GitHub
No data