Vulnerabilities > Adobe

DATE CVE VULNERABILITY TITLE RISK
2020-09-10 CVE-2020-9731 Out-of-bounds Write vulnerability in Adobe Indesign
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions).
local
low complexity
adobe CWE-787
7.8
2020-09-10 CVE-2020-9730 Out-of-bounds Write vulnerability in Adobe Indesign
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions).
local
low complexity
adobe CWE-787
7.8
2020-09-10 CVE-2020-9729 Out-of-bounds Write vulnerability in Adobe Indesign
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions).
local
low complexity
adobe CWE-787
7.8
2020-09-10 CVE-2020-9728 Out-of-bounds Write vulnerability in Adobe Indesign
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions).
local
low complexity
adobe CWE-787
7.8
2020-09-10 CVE-2020-9727 Out-of-bounds Write vulnerability in Adobe Indesign
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions).
local
low complexity
adobe CWE-787
7.8
2020-09-10 CVE-2020-9726 Out-of-bounds Read vulnerability in Adobe Framemaker
Adobe FrameMaker version 2019.0.6 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations.
local
low complexity
adobe CWE-125
6.1
2020-09-10 CVE-2020-9725 Out-of-bounds Write vulnerability in Adobe Framemaker
Adobe FrameMaker version 2019.0.6 (and earlier versions) lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer.
local
low complexity
adobe CWE-787
7.8
2020-09-10 CVE-2020-9743 Cross-site Scripting vulnerability in Adobe Experience Manager
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includes arbitrary HTML code in a parameter value.
network
low complexity
adobe CWE-79
6.1
2020-09-10 CVE-2020-9742 Cross-site Scripting vulnerability in Adobe Experience Manager
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature.
network
low complexity
adobe CWE-79
5.4
2020-09-10 CVE-2020-9741 Cross-site Scripting vulnerability in Adobe Experience Manager
The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component.
network
low complexity
adobe CWE-79
5.4