Vulnerabilities > Adobe > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-04-27 CVE-2017-3066 Deserialization of Untrusted Data vulnerability in Adobe Coldfusion 10.0/11.0/2016
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library.
network
low complexity
adobe CWE-502
critical
9.8
2017-04-12 CVE-2017-3063 Use After Free vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2 NetStream class.
network
low complexity
adobe CWE-416
critical
9.8
2017-04-12 CVE-2017-3062 Use After Free vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property.
network
low complexity
adobe CWE-416
critical
9.8
2017-04-12 CVE-2017-3061 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser.
network
low complexity
adobe CWE-119
critical
9.8
2017-04-12 CVE-2017-3060 Out-of-bounds Read vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser.
network
low complexity
adobe CWE-125
critical
9.8
2017-04-12 CVE-2017-3059 Use After Free vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal script object.
network
low complexity
adobe CWE-416
critical
9.8
2017-04-12 CVE-2017-3037 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JavaScript engine.
network
low complexity
adobe CWE-119
critical
9.8
2017-04-12 CVE-2017-2989 Improper Input Validation vulnerability in Adobe Campaign 6.11
Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campaign database.
network
low complexity
adobe CWE-20
critical
9.1
2017-03-31 CVE-2017-3010 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the rendering engine.
network
low complexity
adobe CWE-119
critical
9.8
2017-02-15 CVE-2017-2973 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Digital Editions
Adobe Digital Editions versions 4.5.3 and earlier have an exploitable heap overflow vulnerability.
network
low complexity
adobe CWE-119
critical
9.8