Impact
An out‑of‑bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file an attacker can trigger the weakness, which may allow reading memory outside the intended bounds and potentially exposing sensitive information. The vulnerability is classified as CWE‑125 and is primarily a confidentiality issue; the attacker could obtain internal memory contents but the CVE description does not cite code execution or denial of service effects.
Affected Systems
The affected product is Canva Affinity on Windows. No specific affected versions are listed in the CVE data; version information is unavailable.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is below 1%, indicating a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply a crafted EMF file, so the likely attack vector is local file or social‑engineering via email attachments. If the vulnerability is exploited, an attacker could read confidential data from memory but no denial of service or arbitrary code execution is described.
OpenCVE Enrichment