CVE-2025-64894

DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this issue to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:adobe:dng_software_development_kit:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

10 Dec 2025, 16:03

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:dng_software_development_kit:*:*:*:*:*:*:*:*
First Time Adobe
Microsoft
Microsoft windows
Apple macos
Apple
Adobe dng Software Development Kit
References () https://helpx.adobe.com/security/products/dng-sdk/apsb25-118.html - () https://helpx.adobe.com/security/products/dng-sdk/apsb25-118.html - Vendor Advisory

09 Dec 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 18:16

Updated : 2025-12-10 16:03


NVD link : CVE-2025-64894

Mitre link : CVE-2025-64894

CVE.ORG link : CVE-2025-64894


JSON object : View

Products Affected

microsoft

  • windows

adobe

  • dng_software_development_kit

apple

  • macos
CWE
CWE-190

Integer Overflow or Wraparound