Adobe After Effects是美国奥多比(Adobe)公司的一套视觉效果和动态图形制作软件。该软件主要用于2D和3D合成、动画制作和视觉特效制作等。 Adobe After Effects 存在操作系统命令注入漏洞。该漏洞源于程序输入验证不正确导致,远程未经身份验证的攻击者可以将特制数据传递到应用程序并在目标系统上执行任意OS命令。以下产品及版本受到影响:Adobe After Effects: 17.0.0、17.0.1、17.0.3、17.0.6、17.1、17.1.1、17.1.3、18.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | After Effects | unspecified ~ 18.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-28580 | 8.8 HIGH | Medium by Adobe file parsing buffer overflow vulnerability could lead to arbitrary code ex |
| CVE-2021-21104 | 8.8 HIGH | Adobe Illustrator memory corruption vulnerability could lead to remote code execution |
| CVE-2021-21105 | 8.8 HIGH | Adobe Illustrator memory corruption vulnerability could lead to remote code execution |
| CVE-2021-28568 | 5.8 MEDIUM | Adobe Genuine Services insecure file permission could lead to privilege escalation |
| CVE-2021-21103 | 4.3 MEDIUM | Adobe Illustrator memory corruption vulnerability could lead to information disclosure |
| CVE-2021-28569 | 4.3 MEDIUM | Adobe Media Encoder VOB file parsing out-of-bounds read could lead to information disclosu |
| CVE-2021-28566 | 3.7 LOW | Magento Commerce information disclosure during upload action leveraging a specially crafte |
| CVE-2021-28581 | Adobe Creative Cloud Desktop uncontrolled search path element vulnerability could lead to | |
| CVE-2021-28567 | Magento Commerce improper authorization allows an authenticated user to perform certain fu |
No comments yet