cisa.gov | Bulletins

Vulnerability Summary for the Week of May 13, 2024

Adobe's Acrobat Reader, Illustrator, and Animate are affected by various vulnerabilities including Use After Free, out-of-bounds read and write, and stack-based buffer overflow issues, which could lead to arbitrary code execution. These vulnerabilities require user interaction, such as opening a malicious file. Adobe's Dreamweaver Desktop has an OS command injection vulnerability that could also lead to code execution. Agentejo's Cockpit CMS has an arbitrary file upload vulnerability, while Apache Friends' XAMPP has an uncontrolled resource consumption vulnerability. ABB's RobotWare 6 has vulnerabilities including out-of-bounds write and NULL pointer dereference issues. 8theme's XStore Core and AA-Team's WZone also have vulnerabilities related to improper privilege management and out-of-bounds write.
favicon
cisa.gov
cisa.gov