CVE-2023-44327


ZDI-CAN-21793: Adobe Bridge MP4 File Uninitialized Variable Information Disclosure Vulnerability

Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.



We have discovered 716 live websites that are affected by CVE-2023-44327.

Contact us to get more info




Affected Software

Product  Bridge
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 14
Total Vulnerable Versions102
Vulnerable Domains716 live websites (97.68% of Bridge install base)


Common Weakness Enumeration


CWE-824 Access of Uninitialized Pointer


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-44327 and the relative popularity of websites


Details

  • Published - Nov 16, 2023
  • Updated - Dec 4, 2023





Countries

United States239 websites



Germany89 websites
Netherlands48 websites
Spain46 websites
France42 websites
Italy38 websites
Australia35 websites
GB30 websites
Canada26 websites
Austria10 websites

TLDs

.com323 websites
.de64 websites
.org39 websites
.nl37 websites
.com.au27 websites
.it25 websites
.es22 websites
.net15 websites
.ca13 websites
.co.uk12 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-44327 through included software libraries and plugins.



References


Websites affected by CVE-2023-44327

Top websites that are affected by CVE-2023-44327. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*********************.com United States*,***
***************.com Netherlands***,***
*******.com United States***,***
***.**********.com United States***,***
***.****.de Germany***,***
********.nz New Zealand***,***
********************.com Germany***,***
*****.**************.com United States***,***
**********.org United States***,***
***.*****.gr Greece***,***
See full domain list