← Back

Adobe

adobe

7,387 CVEs • 184 products

Products (184)

Click to collapse
Toggle
Acrobat Dc
acrobat_dc
Acrobat
acrobat
Air
air
Air Sdk
air_sdk
Reader
reader
Coldfusion
coldfusion
Indesign
indesign
Commerce
commerce
Illustrator
illustrator
Magento
magento
Adobe Air
adobe_air
Bridge
bridge
Commerce B2b
commerce_b2b
Framemaker
framemaker
Dimension
dimension
Animate
animate
Adobe Air Sdk
adobe_air_sdk
Photoshop
photoshop
Photoshop Cc
photoshop_cc
Connect
connect
Media Encoder
media_encoder
Incopy
incopy
Audition
audition
Premiere Pro
premiere_pro
C2pa
c2pa
C2pa Web
c2pa-web
Premiere Rush
premiere_rush
Dreamweaver
dreamweaver
Prelude
prelude
Robohelp
robohelp
Flex
flex
Bridge Cc
bridge_cc
I/o Events
i/o_events
Campaign
campaign
C2patool
c2patool
Lightroom
lightroom
Captivate
captivate
Pagemaker
pagemaker
Jrun
jrun
Livecycle
livecycle
Phonegap
phonegap
Version Cue
version_cue
Acrobat 3d
acrobat_3d
Photoshop Cs4
photoshop_cs4
Acrobat 2017
acrobat_2017
Flex Sdk
flex_sdk
Blazeds
blazeds
Acrobat Xi
acrobat_xi

CVEs (7,387)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Coldfusion
Apr 23, 2026
Dec 12, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%0...Show more
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.Show less
1Adobe
1Coldfusion
Apr 23, 2026
Dec 12, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting err...Show more
Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.Show less
1Adobe
1Download Manager
Apr 23, 2026
Dec 6, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in the Adobe Download Manager before 2.2 allows remote attackers to execute arbitrary code via a long section name in the dm.ini file, which is populated via an AOM file.
1Adobe
1Acrobat Reader
Apr 23, 2026
Dec 3, 2006
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the (1) src, (2) setPageMode, (3) setLayoutMode...Show more
Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the (1) src, (2) setPageMode, (3) setLayoutMode, and (4) setNamedDest methods in an AcroPDF ActiveX control, a different set of vectors than CVE-2006-6027.Show less
1Adobe
1Acrobat Reader
Apr 23, 2026
Nov 21, 2006
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX contr...Show more
Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.Show less
1Adobe
1Adobe Php Ria Sdk
Apr 23, 2026
Oct 26, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in libraries/amfphp/amf-core/custom/CachedGateway.php in Adobe PHP SDK allows remote attackers to execute arbitrary PHP code via the AMFPHP_BASE parameter. NOTE: this issue has be...Show more
PHP remote file inclusion vulnerability in libraries/amfphp/amf-core/custom/CachedGateway.php in Adobe PHP SDK allows remote attackers to execute arbitrary PHP code via the AMFPHP_BASE parameter. NOTE: this issue has been disputed by a third-party researcher who states that AMFPHP_BASE is a constantShow less
1Adobe
1Flash Player
Apr 23, 2026
Oct 17, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify...Show more
CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType. NOTE: the flexibility of the attack varies depending on the type of web browser being used.Show less
1Adobe
1Breeze Licensed Server
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Adobe Breeze 5 Licensed Server and Breeze 5.1 Licensed Server allows attackers to read arbitrary files via unknown vectors related to "URL parsing."
1Adobe
1Contribute
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Adobe Contribute Publishing Server leaks the administrator password in logs that are created during product installation, which allows local users to gain privileges to the server.
1Adobe
1Coldfusion
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors.
1Adobe
1Coldfusion
Apr 16, 2026
Sep 14, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.
1Adobe
1Coldfusion
Apr 16, 2026
Sep 14, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
1Adobe
1Coldfusion
Apr 16, 2026
Sep 14, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted comman...Show more
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command.Show less
1Adobe
1Flash Player
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attackers to bypass the allowScriptAccess protection via unspecified vectors.
1Adobe
2Flash Player
Flex Sdk
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SW...Show more
Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.Show less
1Adobe
1Flash Player
Apr 16, 2026
Jul 13, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to cause a denial of service (browser crash) via a malformed, compressed .swf file, a different issue than CVE-2006-3587.
1Adobe
1Flash Player
Apr 16, 2026
Jul 13, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.
1Adobe
1Acrobat
Apr 16, 2026
Jul 13, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers to execute arbitrary code via unknown vectors in a document that triggers the overflow when it is distilled to PDF.
1Adobe
2Acrobat
Acrobat Reader
Apr 16, 2026
Jul 12, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, which allows local users to gain privileges by overwriting program files.
1Adobe
1Acrobat Reader
Apr 16, 2026
Jun 19, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple unspecified vulnerabilities in Adobe Acrobat Reader (acroread) before 7.0.8 have unknown impact and unknown vectors.