Vulnerabilities > Adobe > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-18 CVE-2021-42268 NULL Pointer Dereference vulnerability in Adobe Animate
Adobe Animate version 21.0.9 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted FLA file.
local
low complexity
adobe CWE-476
5.5
2021-10-15 CVE-2021-39864 Cross-Site Request Forgery (CSRF) vulnerability in Adobe Commerce and Magento Open Source
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link.
network
low complexity
adobe CWE-352
6.5
2021-10-15 CVE-2021-40721 Cross-site Scripting vulnerability in Adobe Connect
Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
network
low complexity
adobe CWE-79
6.1
2021-10-13 CVE-2021-40732 NULL Pointer Dereference vulnerability in multiple products
XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the current user.
local
low complexity
adobe debian CWE-476
6.1
2021-09-29 CVE-2021-39845 Stack-based Buffer Overflow vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the current user.
local
low complexity
adobe CWE-121
6.1
2021-09-29 CVE-2021-39846 Out-of-bounds Write vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the current user.
local
low complexity
adobe CWE-787
6.1
2021-09-29 CVE-2021-39849 NULL Pointer Dereference vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability.
local
low complexity
adobe CWE-476
5.5
2021-09-29 CVE-2021-39850 NULL Pointer Dereference vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability.
local
low complexity
adobe CWE-476
5.5
2021-09-29 CVE-2021-39851 NULL Pointer Dereference vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability.
local
low complexity
adobe CWE-476
5.5
2021-09-29 CVE-2021-39852 NULL Pointer Dereference vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability.
local
low complexity
adobe CWE-476
5.5