Vulnerabilities > Adobe > High

DATE CVE VULNERABILITY TITLE RISK
2023-01-13 CVE-2023-21587 Heap-based Buffer Overflow vulnerability in Adobe Indesign 17.2.1/18.0
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-122
7.8
2023-01-13 CVE-2023-21588 Improper Input Validation vulnerability in Adobe Indesign 17.2.1/18.0
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-20
7.8
2023-01-13 CVE-2023-21589 Out-of-bounds Write vulnerability in Adobe Indesign 17.2.1/18.0
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-787
7.8
2023-01-13 CVE-2023-21590 Out-of-bounds Write vulnerability in Adobe Indesign 17.2.1/18.0
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-787
7.8
2022-10-25 CVE-2022-38435 Improper Input Validation vulnerability in Adobe Illustrator
Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-20
7.8
2022-10-25 CVE-2022-38436 Out-of-bounds Read vulnerability in Adobe Illustrator
Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure.
local
low complexity
adobe CWE-125
7.8
2022-10-20 CVE-2022-42344 Incorrect Authorization vulnerability in multiple products
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability.
network
low complexity
magento adobe CWE-863
8.8
2022-10-14 CVE-2022-38419 XXE vulnerability in Adobe Coldfusion 2018/2021
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read.
network
low complexity
adobe CWE-611
7.5
2022-10-14 CVE-2022-38420 Use of Hard-coded Credentials vulnerability in Adobe Coldfusion 2018/2021
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services.
network
low complexity
adobe CWE-798
7.5
2022-10-14 CVE-2022-38421 Path Traversal vulnerability in Adobe Coldfusion 2018/2021
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user.
network
low complexity
adobe CWE-22
7.2