Vulnerabilities > Adobe > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-12-01 CVE-2017-11284 Deserialization of Untrusted Data vulnerability in Adobe Coldfusion 11.0/2016
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability.
network
low complexity
adobe CWE-502
critical
9.8
2017-12-01 CVE-2017-11283 Deserialization of Untrusted Data vulnerability in Adobe Coldfusion 11.0/2016
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability.
network
low complexity
adobe CWE-502
critical
9.8
2017-12-01 CVE-2017-11282 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser.
network
low complexity
adobe redhat CWE-119
critical
9.8
2017-12-01 CVE-2017-11281 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function.
network
low complexity
adobe redhat CWE-119
critical
9.8
2017-08-11 CVE-2017-3124 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the picture exchange (PCX) file format parsing module.
network
low complexity
adobe CWE-119
critical
9.8
2017-08-11 CVE-2017-3108 Unrestricted Upload of File with Dangerous Type vulnerability in Adobe Experience Manager
Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.
network
low complexity
adobe CWE-434
critical
9.8
2017-08-11 CVE-2017-11274 Use After Free vulnerability in Adobe Digital Editions
Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability.
network
low complexity
adobe CWE-416
critical
9.8
2017-06-27 CVE-2016-0959 Use After Free vulnerability in Adobe products
Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0.267, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 before 20.0.0.267, Adobe Flash Player for Internet Explorer 10 and 11 before 20.0.0.267, Adobe Flash Player for Linux before 11.2.202.559, AIR Desktop Runtime before 20.0.0.233, AIR SDK before 20.0.0.233, AIR SDK & Compiler before 20.0.0.233, AIR for Android before 20.0.0.233.
network
low complexity
adobe CWE-416
critical
9.8
2017-06-20 CVE-2017-3098 Improper Input Validation vulnerability in Adobe Captivate
Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write arbitrary files to the server.
network
low complexity
adobe CWE-20
critical
9.8
2017-06-20 CVE-2017-3097 Uncontrolled Search Path Element vulnerability in Adobe Digital Editions
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability.
network
low complexity
adobe CWE-427
critical
9.8