Vulnerabilities > Adobe

DATE CVE VULNERABILITY TITLE RISK
2016-02-10 CVE-2016-0956 Information Exposure vulnerability in multiple products
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
apache adobe CWE-200
7.5
2016-02-10 CVE-2016-0955 Cross-site Scripting vulnerability in Adobe Experience Manager 6.1.0
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.
network
low complexity
adobe CWE-79
6.1
2016-02-10 CVE-2016-0953 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Bridge CC and Photoshop CC
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.
network
low complexity
adobe CWE-119
critical
9.8
2016-02-10 CVE-2016-0952 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Bridge CC and Photoshop CC
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0953.
network
low complexity
adobe CWE-119
critical
9.8
2016-02-10 CVE-2016-0951 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Bridge CC and Photoshop CC
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.
network
low complexity
adobe CWE-119
critical
9.8
2016-02-10 CVE-2016-0950 7PK - Security Features vulnerability in Adobe Connect
Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.
network
low complexity
adobe CWE-254
5.3
2016-02-10 CVE-2016-0949 Unspecified vulnerability in Adobe Connect
Adobe Connect before 9.5.2 allows remote attackers to have an unspecified impact via a crafted parameter in a URL.
network
low complexity
adobe
critical
9.8
2016-02-10 CVE-2016-0948 Cross-Site Request Forgery (CSRF) vulnerability in Adobe Connect
Cross-site request forgery (CSRF) vulnerability in Adobe Connect before 9.5.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
network
low complexity
adobe CWE-352
8.8
2016-01-14 CVE-2016-0947 Unspecified vulnerability in Adobe products
Untrusted search path vulnerability in Adobe Download Manager, as used in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X, allows local users to gain privileges via a crafted resource in an unspecified directory.
local
low complexity
adobe
7.8
2016-01-14 CVE-2016-0946 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0931, CVE-2016-0933, CVE-2016-0936, CVE-2016-0938, CVE-2016-0939, CVE-2016-0942, CVE-2016-0944, and CVE-2016-0945.
network
low complexity
adobe CWE-119
critical
9.8