Vulnerabilities > Adobe

DATE CVE VULNERABILITY TITLE RISK
2022-01-13 CVE-2021-44176 Cross-site Scripting vulnerability in Adobe products
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe CWE-79
6.1
2022-01-13 CVE-2021-44177 Cross-site Scripting vulnerability in Adobe products
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe CWE-79
6.1
2022-01-13 CVE-2021-44178 Cross-site Scripting vulnerability in Adobe products
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a reflected Cross-Site Scripting (XSS) vulnerability via the itemResourceType parameter.
network
low complexity
adobe CWE-79
6.1
2022-01-13 CVE-2021-45053 Out-of-bounds Write vulnerability in Adobe Incopy 15.1.3/16.0/16.4
Adobe InCopy version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-787
7.8
2022-01-13 CVE-2021-45054 Use After Free vulnerability in Adobe Incopy 15.1.3/16.0/16.4
Adobe InCopy version 16.4 (and earlier) is affected by a use-after-free vulnerability in the processing of a JPEG2000 file that could lead to disclosure of sensitive memory.
local
low complexity
adobe CWE-416
5.5
2022-01-13 CVE-2021-45055 Out-of-bounds Read vulnerability in Adobe Incopy 15.1.3/16.0/16.4
Adobe InCopy version 16.4 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure.
local
low complexity
adobe CWE-125
7.8
2022-01-13 CVE-2021-45056 Out-of-bounds Write vulnerability in Adobe Incopy 15.1.3/16.0/16.4
Adobe InCopy version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-787
7.8
2022-01-13 CVE-2021-45057 Out-of-bounds Write vulnerability in Adobe Indesign
Adobe InDesign version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-787
7.8
2022-01-13 CVE-2021-45058 Out-of-bounds Write vulnerability in Adobe Indesign
Adobe InDesign version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-787
7.8
2022-01-13 CVE-2021-45059 Use After Free vulnerability in Adobe Indesign
Adobe InDesign version 16.4 (and earlier) is affected by a use-after-free vulnerability in the processing of a JPEG2000 file that could lead to disclosure of sensitive memory.
local
low complexity
adobe CWE-416
3.3