CVE-2025-27193

Name
CVE-2025-27193
Description
Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://helpx.adobe.com/security/products/bridge/apsb25-25.html

Match rules

CPE URI Source package Min version Max version
bridge >= 0 <= 15.0.2
cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:* adobe-bridge >= None < 14.1.6
cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:* adobe-bridge >= 15.0 < 15.0.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
bridge edge-main 1.5-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable