Vulnerabilities > Adobe > High

DATE CVE VULNERABILITY TITLE RISK
2021-10-04 CVE-2021-36051 Heap-based Buffer Overflow vulnerability in multiple products
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user.
local
low complexity
adobe debian CWE-122
7.8
2021-09-29 CVE-2021-35982 Uncontrolled Search Path Element vulnerability in Adobe Acrobat DC and Acrobat Reader DC
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability.
local
low complexity
adobe CWE-427
7.3
2021-09-29 CVE-2021-39836 Use After Free vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetIcon action that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-416
7.8
2021-09-08 CVE-2021-21103 Out-of-bounds Write vulnerability in Adobe Illustrator
Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file.
network
low complexity
adobe CWE-787
8.8
2021-09-08 CVE-2021-21104 Out-of-bounds Write vulnerability in Adobe Illustrator
Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file.
network
low complexity
adobe CWE-787
8.8
2021-09-08 CVE-2021-21105 Out-of-bounds Write vulnerability in Adobe Illustrator
Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file.
network
low complexity
adobe CWE-787
8.8
2021-09-08 CVE-2021-28571 OS Command Injection vulnerability in Adobe After Effects
Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debugging tool for JavaScript scripts.
network
high complexity
adobe CWE-78
7.6
2021-09-02 CVE-2021-28550 Use After Free vulnerability in Adobe products
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability.
network
low complexity
adobe CWE-416
8.8
2021-09-02 CVE-2021-28553 Use After Free vulnerability in Adobe products
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Use After Free vulnerability.
network
low complexity
adobe CWE-416
8.8
2021-09-02 CVE-2021-35996 Out-of-bounds Write vulnerability in Adobe After Effects
Adobe After Effects version 18.2.1 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file.
local
low complexity
adobe CWE-787
7.8