CVE-2025-54270Medium· 5.5▾ SunlitAnimate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitati…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
animate >= 23.0.0, < 23.0.15animate >= 24.0.0, < 24.0.12Upgrade past the affected range:
animate 24.0.12Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61804High· 7.8Animate versions 23.0.13, 24.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2025-54279High· 7.8Animate versions 23.0.13, 24.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2025-54269Medium· 5.5Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure
CVE-2026-76192Medium· 5.5InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service
CVE-2026-84396Medium· 5.5InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service
CVE-2026-76191High· 8.2Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user