Lucene search

K
osvGoogleOSV:CVE-2021-40716
HistorySep 29, 2021 - 4:15 p.m.

CVE-2021-40716

2021-09-2916:15:11
Google
osv.dev
5
xmp toolkit sdk
vulnerability
out-of-bounds read
sensitive memory disclosure
aslr bypass
user interaction
exploitation

AI Score

5.7

Confidence

Low

EPSS

0.002

Percentile

60.4%

XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

AI Score

5.7

Confidence

Low

EPSS

0.002

Percentile

60.4%