← Back

Adobe

adobe

7,387 CVEs • 184 products

Products (184)

Click to collapse
Toggle
Acrobat Dc
acrobat_dc
Acrobat
acrobat
Air
air
Air Sdk
air_sdk
Reader
reader
Coldfusion
coldfusion
Indesign
indesign
Commerce
commerce
Illustrator
illustrator
Magento
magento
Adobe Air
adobe_air
Bridge
bridge
Commerce B2b
commerce_b2b
Framemaker
framemaker
Dimension
dimension
Animate
animate
Adobe Air Sdk
adobe_air_sdk
Photoshop
photoshop
Photoshop Cc
photoshop_cc
Connect
connect
Media Encoder
media_encoder
Incopy
incopy
Audition
audition
Premiere Pro
premiere_pro
C2pa
c2pa
C2pa Web
c2pa-web
Premiere Rush
premiere_rush
Dreamweaver
dreamweaver
Prelude
prelude
Robohelp
robohelp
Flex
flex
Bridge Cc
bridge_cc
I/o Events
i/o_events
Campaign
campaign
C2patool
c2patool
Lightroom
lightroom
Captivate
captivate
Pagemaker
pagemaker
Jrun
jrun
Livecycle
livecycle
Phonegap
phonegap
Version Cue
version_cue
Acrobat 3d
acrobat_3d
Photoshop Cs4
photoshop_cs4
Acrobat 2017
acrobat_2017
Flex Sdk
flex_sdk
Blazeds
blazeds
Acrobat Xi
acrobat_xi

CVEs (7,387)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to bypass intended Trust Manager restrictions via unspecified vectors.
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Integer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted documen...Show more
Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document.Show less
1Adobe
3Acrobat
Acrobat ReaderReader
May 21, 2026
Oct 13, 2009
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as e...Show more
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.Show less
1Adobe
1Photoshop Elements
Apr 23, 2026
Sep 30, 2009
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands a...Show more
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Sep 25, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and earlier 8.x versions; and possibly 7.1.4 and earlier 7.x versions allows remote attackers to cause a de...Show more
Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and earlier 8.x versions; and possibly 7.1.4 and earlier 7.x versions allows remote attackers to cause a denial of service (application crash) via a PDF file with a large number of [ (open square bracket) characters in the argument to the alert method. NOTE: some of these details are obtained from third party information.Show less
1Adobe
1Shockwave Player
Apr 23, 2026
Sep 18, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersi...Show more
Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.Show less
1Adobe
1Robohelp Server
Apr 23, 2026
Sep 4, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH...Show more
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vd_adobe module in VulnDisco Pack Professional 8.7 through 8.11.Show less
1Adobe
1Flex Sdk
Apr 23, 2026
Aug 21, 2009
N/A· v4
N/A· v3
2.6 LOW· v2
Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value,...Show more
Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to inject arbitrary web script or HTML via the query string.Show less
1Adobe
1Coldfusion
Apr 23, 2026
Aug 18, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
1Adobe
1Coldfusion
Apr 23, 2026
Aug 18, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875.
1Adobe
1Coldfusion
Apr 23, 2026
Aug 18, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspecified vectors, related to a "double-encoded null character vulnerability."
1Adobe
1Coldfusion
Apr 23, 2026
Aug 18, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-187...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1877.Show less
1Adobe
1Jrun
Apr 23, 2026
Aug 18, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Adobe JRun 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Adobe
1Jrun
Apr 23, 2026
Aug 18, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the logfil...Show more
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the logfile parameter.Show less
1Adobe
1Coldfusion
Apr 23, 2026
Aug 18, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.Show less
1Adobe
3Air
Flash PlayerFlex
Apr 23, 2026
Jul 31, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to obtain sensitive information via vectors involving saving an SWF file to a hard drive, related to a "local s...Show more
Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to obtain sensitive information via vectors involving saving an SWF file to a hard drive, related to a "local sandbox vulnerability."Show less
1Adobe
3Air
Flash PlayerFlex
Apr 23, 2026
Jul 31, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (a...Show more
Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2 file with a large intrf_count value that triggers a dereference of an out-of-bounds pointer.Show less
1Adobe
3Air
Flash PlayerFlex
Apr 23, 2026
Jul 31, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary co...Show more
Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing.Show less
1Adobe
3Air
Flash PlayerFlex
Apr 23, 2026
Jul 31, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "clickjacking vulnerability....Show more
Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "clickjacking vulnerability."Show less