← Back

Adobe

adobe

7,498 CVEs • 184 products

Products (184)

Click to collapse
Toggle
Acrobat Dc
acrobat_dc
Acrobat
acrobat
Air
air
Air Sdk
air_sdk
Reader
reader
Coldfusion
coldfusion
Indesign
indesign
Commerce
commerce
Illustrator
illustrator
Magento
magento
Bridge
bridge
Adobe Air
adobe_air
Commerce B2b
commerce_b2b
Framemaker
framemaker
Dimension
dimension
Animate
animate
Adobe Air Sdk
adobe_air_sdk
Photoshop
photoshop
Photoshop Cc
photoshop_cc
Connect
connect
Media Encoder
media_encoder
Incopy
incopy
C2pa
c2pa
C2pa Web
c2pa-web
Audition
audition
Premiere Pro
premiere_pro
C2patool
c2patool
Campaign
campaign
Premiere Rush
premiere_rush
Dreamweaver
dreamweaver
Prelude
prelude
Lightroom
lightroom
Robohelp
robohelp
Flex
flex
Bridge Cc
bridge_cc
I/o Events
i/o_events
Captivate
captivate
Pagemaker
pagemaker
Jrun
jrun
Livecycle
livecycle
Phonegap
phonegap
Version Cue
version_cue
Acrobat 3d
acrobat_3d
Photoshop Cs4
photoshop_cs4
Acrobat 2017
acrobat_2017
Premiere
premiere
Flex Sdk
flex_sdk
Blazeds
blazeds

CVEs (7,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Coldfusion
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors.
1Adobe
1Coldfusion
Apr 16, 2026
Sep 14, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.
1Adobe
1Coldfusion
Apr 16, 2026
Sep 14, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
1Adobe
1Coldfusion
Apr 16, 2026
Sep 14, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted comman...Show more
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command.Show less
1Adobe
1Flash Player
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attackers to bypass the allowScriptAccess protection via unspecified vectors.
1Adobe
2Flash Player
Flex Sdk
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SW...Show more
Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.Show less
1Adobe
1Flash Player
Apr 16, 2026
Jul 13, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to cause a denial of service (browser crash) via a malformed, compressed .swf file, a different issue than CVE-2006-3587.
1Adobe
1Flash Player
Apr 16, 2026
Jul 13, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.
1Adobe
1Acrobat
Apr 16, 2026
Jul 13, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers to execute arbitrary code via unknown vectors in a document that triggers the overflow when it is distilled to PDF.
1Adobe
2Acrobat
Acrobat Reader
Apr 16, 2026
Jul 12, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, which allows local users to gain privileges by overwriting program files.
1Adobe
1Acrobat Reader
Apr 16, 2026
Jun 19, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple unspecified vulnerabilities in Adobe Acrobat Reader (acroread) before 7.0.8 have unknown impact and unknown vectors.
1Adobe
1Dreamweaver
Apr 16, 2026
May 9, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Adobe Dreamweaver 8 before 8.0.2 and MX 2004 can generate code that allows SQL injection attacks in the (1) ColdFusion, (2) PHP mySQL, (3) ASP, (4) ASP.NET, and (5) JSP server models.
1Adobe
1Document Server
Apr 16, 2026
Apr 13, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs...Show more
Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs via brute force attacks.Show less
1Adobe
1Document Server
Apr 16, 2026
Apr 13, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote attackers to gain access to PDF files that are being processed within that session.
1Adobe
1Document Server
Apr 16, 2026
Apr 13, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op pa...Show more
Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op parameter in AlterCast. NOTE: it is not clear whether the vendor advisory addresses this issue.Show less
1Adobe
1Document Server
Apr 16, 2026
Apr 13, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ad...Show more
Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear whether the vendor advisory addresses this issue. In addition, since the issue requires administrative privileges to exploit, it is not clear whether this crosses security boundaries.Show less
1Adobe
1Livecycle Form Manager
Apr 16, 2026
Apr 13, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked "OBSOLETE" but the account is also active, within the authentication...Show more
Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked "OBSOLETE" but the account is also active, within the authentication system.Show less
1Adobe
1Acrobat Reader
Apr 16, 2026
Apr 13, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters. NOTE...Show more
Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters. NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues. Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure.Show less
1Adobe
2Document Server
Graphics Server
Apr 16, 2026
Mar 16, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP...Show more
Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command.Show less
1Adobe
9Acrobat
Acrobat ReaderCreative Suite+6 more
Apr 16, 2026
Feb 2, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local...Show more
Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.Show less