Back

HIGH

DNG SDK | Heap-based Buffer Overflow (CWE-122)

Published Dec 9, 2025

Description

DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner adobe
Published Dec 9, 2025
Updated Dec 9, 2025
Reserved Nov 11, 2025

CISA Vulnrichment

Updated Dec 9, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner adobe
Published Dec 9, 2025
Updated Dec 9, 2025

GitHub

No data