DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
History

Wed, 10 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe dng Software Development Kit
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:dng_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe dng Software Development Kit
Apple
Apple macos
Microsoft
Microsoft windows

Tue, 09 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
Description DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title DNG SDK | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2025-12-09T17:41:45.197Z

Updated: 2025-12-09T19:02:59.942Z

Reserved: 2025-11-11T22:48:38.823Z

Link: CVE-2025-64784

cve-icon Vulnrichment

Updated: 2025-12-09T19:02:56.194Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-09T18:16:07.640

Modified: 2025-12-10T16:03:18.187

Link: CVE-2025-64784

cve-icon Redhat

No data.