Vulnerabilities > Adobe > High

DATE CVE VULNERABILITY TITLE RISK
2021-11-18 CVE-2021-40759 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe After Effects
Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-119
7.8
2021-11-18 CVE-2021-42266 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Animate
Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious FLA file, potentially resulting in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-119
7.8
2021-11-17 CVE-2021-40745 Unspecified vulnerability in Adobe Campaign
Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files.
network
low complexity
adobe
7.5
2021-11-16 CVE-2021-42723 Out-of-bounds Read vulnerability in Adobe Premiere PRO
Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted SGI file, which could result in a read past the end of an allocated memory structure.
local
low complexity
adobe CWE-125
7.8
2021-11-16 CVE-2021-42731 Unspecified vulnerability in Adobe Indesign
Adobe InDesign versions 16.4 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted file.
local
low complexity
adobe
7.8
2021-11-16 CVE-2021-42721 Use After Free vulnerability in Adobe Media Encoder
Acrobat Bridge versions 11.1.1 and earlier are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-416
7.8
2021-11-16 CVE-2021-42726 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Media Encoder
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user.
local
low complexity
adobe CWE-119
7.8
2021-10-15 CVE-2021-40724 Path Traversal vulnerability in Adobe Acrobat Reader
Acrobat Reader for Android versions 21.8.0 (and earlier) are affected by a Path traversal vulnerability.
local
low complexity
adobe CWE-22
7.8
2021-09-29 CVE-2021-35982 Unspecified vulnerability in Adobe Acrobat DC and Acrobat Reader DC
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability.
local
low complexity
adobe
7.3
2021-09-29 CVE-2021-39836 Unspecified vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetIcon action that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe
7.8