← Back

Adobe

adobe

7,498 CVEs • 184 products

Products (184)

Click to collapse
Toggle
Acrobat Dc
acrobat_dc
Acrobat
acrobat
Air
air
Air Sdk
air_sdk
Reader
reader
Coldfusion
coldfusion
Indesign
indesign
Commerce
commerce
Illustrator
illustrator
Magento
magento
Bridge
bridge
Adobe Air
adobe_air
Commerce B2b
commerce_b2b
Framemaker
framemaker
Dimension
dimension
Animate
animate
Adobe Air Sdk
adobe_air_sdk
Photoshop
photoshop
Photoshop Cc
photoshop_cc
Connect
connect
Media Encoder
media_encoder
Incopy
incopy
C2pa
c2pa
C2pa Web
c2pa-web
Audition
audition
Premiere Pro
premiere_pro
C2patool
c2patool
Campaign
campaign
Premiere Rush
premiere_rush
Dreamweaver
dreamweaver
Prelude
prelude
Lightroom
lightroom
Robohelp
robohelp
Flex
flex
Bridge Cc
bridge_cc
I/o Events
i/o_events
Captivate
captivate
Pagemaker
pagemaker
Jrun
jrun
Livecycle
livecycle
Phonegap
phonegap
Version Cue
version_cue
Acrobat 3d
acrobat_3d
Photoshop Cs4
photoshop_cs4
Acrobat 2017
acrobat_2017
Premiere
premiere
Flex Sdk
flex_sdk
Blazeds
blazeds

CVEs (7,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Acrobat Reader
Apr 22, 2026
Mar 19, 2009
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab o...Show more
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.Show less
1Adobe
2Robohelp
Robohelp Server
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6 and 7, and RoboHelp Server 6 and 7, allows remote attackers to inject arbitrary web script or HTML via vectors involving files produced by RoboHelp.
1Adobe
2Robohelp
Robohelp Server
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors lo...Show more
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log.Show less
1Adobe
4Air
Flash PlayerFlash Player For Linux+1 more
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related...Show more
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related to a "Clickjacking attack."Show less
1Adobe
1Flash Player For Linux
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a director...Show more
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.Show less
1Adobe
4Air
Flash PlayerFlash Player For Linux+1 more
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code...Show more
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."Show less
1Adobe
4Air
Flash PlayerFlash Player For Linux+1 more
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a crafted Shockw...Show more
Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a crafted Shockwave Flash (aka .swf) file.Show less
1Adobe
4Air
Flash PlayerFlash Player For Linux+1 more
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL...Show more
Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant."Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Feb 20, 2009
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedd...Show more
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.Show less
1Adobe
1Dreamweaver
Apr 23, 2026
Feb 5, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web...Show more
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web script or HTML via an asfunction: URI in the skinName parameter. NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or CVE-2007-6637.Show less
1Adobe
1Flash Player For Linux
Apr 23, 2026
Dec 18, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file.
1Adobe
2Air
Flash Player
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure...Show more
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.Show less
1Adobe
2Air
Flash Player
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value for a "constant count,...Show more
The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value for a "constant count," which allows remote attackers to read sensitive data from process memory via a crafted PDF file.Show less
1Adobe
2Air
Flash Player
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) Acti...Show more
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file.Show less
1Adobe
1Acrobat
Apr 23, 2026
Dec 5, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document's password via a brute-force attack.
1Adobe
1Flash Media Server
Apr 23, 2026
Nov 25, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via strea...Show more
The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.Show less
1Adobe
1Adobe Air
Apr 23, 2026
Nov 17, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in Adobe AIR 1.1 and earlier allows context-dependent attackers to execute untrusted JavaScript in an AIR application via unknown attack vectors.
1Adobe
1Flash Player
Apr 23, 2026
Nov 17, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."
1Adobe
1Coldfusion
Apr 23, 2026
Nov 10, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified vulnerability in Adobe ColdFusion 8 and 8.0.1 and ColdFusion MX 7.0.2 allows local users to bypass sandbox restrictions, and obtain sensitive information or possibly gain privileges, via unknown vectors.
1Adobe
1Flash Player
Apr 23, 2026
Nov 10, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to loose interpretation of an ActionScript attribute...Show more
Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to loose interpretation of an ActionScript attribute.Show less