Vulnerabilities > Adobe

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-3103 Cross-site Scripting vulnerability in Adobe Connect
Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability.
network
low complexity
adobe CWE-79
6.1
2017-07-17 CVE-2017-3102 Cross-site Scripting vulnerability in Adobe Connect
Adobe Connect versions 9.6.1 and earlier have a reflected cross-site scripting vulnerability.
network
low complexity
adobe CWE-79
6.1
2017-07-17 CVE-2017-3101 Unspecified vulnerability in Adobe Connect
Adobe Connect versions 9.6.1 and earlier have a clickjacking vulnerability.
network
low complexity
adobe
7.5
2017-07-17 CVE-2017-3100 Out-of-bounds Write vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 2 BitmapData class.
network
low complexity
adobe CWE-787
6.5
2017-07-17 CVE-2017-3099 Out-of-bounds Write vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 3 raster data model.
network
low complexity
adobe CWE-787
8.8
2017-07-17 CVE-2017-3080 Unspecified vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to the Flash API used by Internet Explorer.
network
low complexity
adobe
6.5
2017-06-27 CVE-2016-0959 Use After Free vulnerability in Adobe products
Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0.267, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 before 20.0.0.267, Adobe Flash Player for Internet Explorer 10 and 11 before 20.0.0.267, Adobe Flash Player for Linux before 11.2.202.559, AIR Desktop Runtime before 20.0.0.233, AIR SDK before 20.0.0.233, AIR SDK & Compiler before 20.0.0.233, AIR for Android before 20.0.0.233.
network
low complexity
adobe CWE-416
critical
9.8
2017-06-20 CVE-2017-3098 Improper Input Validation vulnerability in Adobe Captivate
Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write arbitrary files to the server.
network
low complexity
adobe CWE-20
critical
9.8
2017-06-20 CVE-2017-3097 Uncontrolled Search Path Element vulnerability in Adobe Digital Editions
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
network
low complexity
adobe CWE-427
critical
9.8
2017-06-20 CVE-2017-3096 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Digital Editions
Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the character code mapping module.
network
low complexity
adobe CWE-119
critical
9.8