Vulnerabilities > Adobe

DATE CVE VULNERABILITY TITLE RISK
2007-09-21 CVE-2007-5020 Code Injection vulnerability in Adobe Acrobat and Acrobat Reader
Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP.
network
adobe CWE-94
critical
9.3
2007-09-12 CVE-2007-4651 Permissions, Privileges, and Access Controls vulnerability in Adobe Connect Enterprise Server 6
Unspecified vulnerability in Adobe Connect Enterprise Server 6 allows remote attackers to read certain pages that are restricted to the administrator via unknown vectors.
network
low complexity
adobe CWE-264
5.0
2007-08-14 CVE-2007-4324 Permissions, Privileges, and Access Controls vulnerability in Adobe Flash Player
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not.
network
low complexity
adobe CWE-264
5.0
2007-07-11 CVE-2007-3457 Cross-Site Request Forgery (CSRF) vulnerability in Adobe Flash Player
Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.
network
adobe CWE-352
4.3
2007-07-11 CVE-2007-3456 Numeric Errors vulnerability in Adobe Flash Player
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.
network
adobe CWE-189
critical
9.3
2007-07-10 CVE-2007-3640 Cross-Site Scripting vulnerability in Adobe AIR
Adobe Integrated Runtime (AIR, aka Apollo) allows context-dependent attackers to modify arbitrary files within an executing .air file (compiled AIR application) and perform cross-site scripting (XSS) attacks, as demonstrated by an application that modifies an HTML file inside itself via JavaScript that uses an APPEND open operation and the writeUTFBytes function.
network
adobe
4.3
2007-05-18 CVE-2007-2682 Unspecified vulnerability in Adobe Creative Suite 3.0
The installer for Adobe Version Cue CS3 Server on Apple Mac OS X, as used in Adobe Creative Suite 3 (CS3), does not re-enable the personal firewall after completing the product installation, which allows remote attackers to bypass intended firewall rules.
network
low complexity
apple adobe
7.5
2007-05-10 CVE-2007-1280 Cross-Site Scripting vulnerability in Adobe Robohelp and Robohelp Server
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2) whcsh_home.htm in WebHelp, (3) wf_startpage.js and (4) wf_startqs.htm in FlashHelp, or (5) WindowManager.dll in RoboHelp Server 6.
network
microsoft adobe
4.3
2007-04-30 CVE-2007-2365 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe products
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
network
adobe CWE-119
critical
9.3
2007-04-25 CVE-2007-2244 Buffer Errors vulnerability in Adobe Golive, Illustrator and Photoshop
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.
network
adobe CWE-119
critical
9.3