← Back

Adobe

adobe

7,498 CVEs • 184 products

Products (184)

Click to collapse
Toggle
Acrobat Dc
acrobat_dc
Acrobat
acrobat
Air
air
Air Sdk
air_sdk
Reader
reader
Coldfusion
coldfusion
Indesign
indesign
Commerce
commerce
Illustrator
illustrator
Magento
magento
Bridge
bridge
Adobe Air
adobe_air
Commerce B2b
commerce_b2b
Framemaker
framemaker
Dimension
dimension
Animate
animate
Adobe Air Sdk
adobe_air_sdk
Photoshop
photoshop
Photoshop Cc
photoshop_cc
Connect
connect
Media Encoder
media_encoder
Incopy
incopy
C2pa
c2pa
C2pa Web
c2pa-web
Audition
audition
Premiere Pro
premiere_pro
C2patool
c2patool
Campaign
campaign
Premiere Rush
premiere_rush
Dreamweaver
dreamweaver
Prelude
prelude
Lightroom
lightroom
Robohelp
robohelp
Flex
flex
Bridge Cc
bridge_cc
I/o Events
i/o_events
Captivate
captivate
Pagemaker
pagemaker
Jrun
jrun
Livecycle
livecycle
Phonegap
phonegap
Version Cue
version_cue
Acrobat 3d
acrobat_3d
Photoshop Cs4
photoshop_cs4
Acrobat 2017
acrobat_2017
Premiere
premiere
Flex Sdk
flex_sdk
Blazeds
blazeds

CVEs (7,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Flash Player
Apr 23, 2026
Nov 10, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Adobe Flash Player 9.0.124.0 and earlier does not properly interpret policy files, which allows remote attackers to bypass a non-root domain policy.
1Adobe
1Flash Player
Apr 23, 2026
Nov 10, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Adobe Flash Player 9.0.124.0 and earlier, when a Mozilla browser is used, does not properly interpret jar: URLs, which allows attackers to obtain sensitive information via unknown vectors.
1Adobe
1Flash Player
Apr 23, 2026
Nov 10, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors.
1Adobe
1Flash Player
Apr 23, 2026
Nov 10, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in Adobe Flash Player 9.0.124.0 and earlier makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.
1Adobe
1Flash Player
Apr 23, 2026
Nov 10, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP response headers.
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Nov 5, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, trig...Show more
The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Nov 5, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via unknown vectors.
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Nov 5, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an in...Show more
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Nov 5, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in a JavaScript method in Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allows remote attackers to execute arbitrary code via unknown vectors, related to an "input validation iss...Show more
Unspecified vulnerability in a JavaScript method in Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allows remote attackers to execute arbitrary code via unknown vectors, related to an "input validation issue."Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Nov 5, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allow remote attackers to execute arbitrary code via a crafted PDF document that (1) performs unspecified actions on a Collab object that trigger memory corru...Show more
Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allow remote attackers to execute arbitrary code via a crafted PDF document that (1) performs unspecified actions on a Collab object that trigger memory corruption, related to a GetCosObj method; or (2) contains a malformed PDF object that triggers memory corruption during parsing.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Nov 5, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Array index error in Adobe Reader and Acrobat, and the Explorer extension (aka AcroRd32Info), 8.1.2, 8.1.1, and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that triggers an out-of...Show more
Array index error in Adobe Reader and Acrobat, and the Explorer extension (aka AcroRd32Info), 8.1.2, 8.1.1, and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that triggers an out-of-bounds write, related to parsing of Type 1 fonts.Show less
2Adobe
Oracle
3Acrobat
Acrobat ReaderSolaris
Apr 22, 2026
Nov 4, 2008
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argum...Show more
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.Show less
1Adobe
1Pagemaker
Apr 23, 2026
Oct 31, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in AldFs32.dll in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a malformed .PMD file, related to "Key Strings," a different vulnerability...Show more
Stack-based buffer overflow in AldFs32.dll in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a malformed .PMD file, related to "Key Strings," a different vulnerability than CVE-2007-5169 and CVE-2007-5394.Show less
1Adobe
1Pagemaker
Apr 23, 2026
Oct 30, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .PMD file with a crafted font structure.
1Adobe
1Pagemaker
Apr 23, 2026
Oct 30, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in AldFs32.dll in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .PMD file with a crafted font structure, a different vulnerability than...Show more
Stack-based buffer overflow in AldFs32.dll in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .PMD file with a crafted font structure, a different vulnerability than CVE-2007-5169 and CVE-2007-6432.Show less
1Adobe
1Flash Player
Apr 23, 2026
Oct 17, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 allow remote attackers to execute arbitrary code via an SWF file containing long control parameters.
1Adobe
1Flash Player
Apr 23, 2026
Oct 17, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download oper...Show more
ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file.Show less
1Adobe
1Flash Player
Apr 23, 2026
Oct 14, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a differe...Show more
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.Show less
1Adobe
1Flash Player
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as dem...Show more
The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."Show less
1Adobe
1Flash Player
Apr 23, 2026
Oct 6, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF file with unspecified "Filter evasion" manipulations.