Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adobe
Adobe dimension Apple Apple macos Microsoft Microsoft windows |
|
CPEs | cpe:2.3:a:adobe:dimension:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Adobe
Adobe dimension Apple Apple macos Microsoft Microsoft windows |
Tue, 08 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Jul 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
Title | Dimension | Out-of-bounds Read (CWE-125) | |
Weaknesses | CWE-125 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: adobe
Published: 2025-07-08T17:29:23.456Z
Updated: 2025-07-08T17:52:20.471Z
Reserved: 2025-04-30T20:47:55.003Z
Link: CVE-2025-47135

Updated: 2025-07-08T17:51:27.134Z

Status : Analyzed
Published: 2025-07-08T18:15:29.440
Modified: 2025-07-11T17:45:31.787
Link: CVE-2025-47135

No data.