XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
"2026-04-12T14:42:33Z"
[
{
"source": "https://github.com/adobe/xmp-toolkit-sdk/commit/581c41213ddcee1fbc72cbb532531102a6617a25",
"target": {
"file": "XMPFiles/source/FormatSupport/ReconcileTIFF.cpp"
},
"id": "CVE-2025-30305-0fdc4107",
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"126636771179267164347849124104795878245",
"146311462694702441864604298611546141686",
"229694796421047086589626576460393590208",
"333049585819998709432590915625886727448",
"327344094990431339669481462780498307920",
"185860195157659454465178398241492620444",
"27437563912872136019565540546888073161"
],
"threshold": 0.9
}
},
{
"source": "https://github.com/adobe/xmp-toolkit-sdk/commit/581c41213ddcee1fbc72cbb532531102a6617a25",
"target": {
"function": "MPEG4_MetaHandler::ParseTimecodeTrack",
"file": "XMPFiles/source/FileHandlers/MPEG4_Handler.cpp"
},
"id": "CVE-2025-30305-2278309c",
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "221465110125069646214356567680915949747",
"length": 4953.0
}
},
{
"source": "https://github.com/adobe/xmp-toolkit-sdk/commit/581c41213ddcee1fbc72cbb532531102a6617a25",
"target": {
"file": "XMPFiles/source/FormatSupport/TIFF_MemoryReader.cpp"
},
"id": "CVE-2025-30305-3b510a9b",
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"187518944139985249420273412500574211097",
"15583002584226428710291704495432648427",
"205985667509089914986957604550275770335"
],
"threshold": 0.9
}
},
{
"source": "https://github.com/adobe/xmp-toolkit-sdk/commit/581c41213ddcee1fbc72cbb532531102a6617a25",
"target": {
"file": "XMPFiles/source/FileHandlers/MPEG4_Handler.cpp"
},
"id": "CVE-2025-30305-7b21aa7d",
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"125129654406807451222550634922981563100",
"9544207699385971335663201338877825513",
"311545938769563290809438059876576815640",
"131638305182527215685738375823343845434",
"296059875309506548659418954941307465628",
"317752850298652022554702432266603748686"
],
"threshold": 0.9
}
},
{
"source": "https://github.com/adobe/xmp-toolkit-sdk/commit/581c41213ddcee1fbc72cbb532531102a6617a25",
"target": {
"function": "ImportConversionTable",
"file": "XMPFiles/source/FormatSupport/ReconcileTIFF.cpp"
},
"id": "CVE-2025-30305-c5dfc716",
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "103952551366490071579651973526231604574",
"length": 2190.0
}
},
{
"source": "https://github.com/adobe/xmp-toolkit-sdk/commit/581c41213ddcee1fbc72cbb532531102a6617a25",
"target": {
"function": "TIFF_MemoryReader::GetTag",
"file": "XMPFiles/source/FormatSupport/TIFF_MemoryReader.cpp"
},
"id": "CVE-2025-30305-e38fa175",
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "1182487954308599792182195617916173662",
"length": 576.0
}
},
{
"source": "https://github.com/adobe/xmp-toolkit-sdk/commit/581c41213ddcee1fbc72cbb532531102a6617a25",
"target": {
"function": "ASF_Support::ReadHeaderObject",
"file": "XMPFiles/source/FormatSupport/ASF_Support.cpp"
},
"id": "CVE-2025-30305-ede195aa",
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "203380090588908134117353179680189655717",
"length": 4395.0
}
},
{
"source": "https://github.com/adobe/xmp-toolkit-sdk/commit/581c41213ddcee1fbc72cbb532531102a6617a25",
"target": {
"file": "XMPFiles/source/FormatSupport/ASF_Support.cpp"
},
"id": "CVE-2025-30305-f4450138",
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"270222890788802721821863585226932284769",
"197411064336870393814664177552957050643",
"46555676254762346810097850001586770172",
"162603547392460467271159842841031210326",
"86296364783011747475092427852147418728",
"151231048613982874318140143371889519049",
"273233510198261307236627151114006245917",
"9058603271038788767604125618184217002"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30305.json"