Vulnerabilities > Adobe > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-18 CVE-2021-43017 Creation of Temporary File in Directory with Incorrect Permissions vulnerability in Adobe Creative Cloud Desktop Application
Adobe Creative Cloud version 5.5 (and earlier) are affected by an Application denial of service vulnerability in the Creative Cloud Desktop installer.
local
low complexity
adobe CWE-379
4.2
2021-11-18 CVE-2021-40756 NULL Pointer Dereference vulnerability in Adobe After Effects
Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file.
local
low complexity
adobe CWE-476
5.5
2021-11-18 CVE-2021-40761 NULL Pointer Dereference vulnerability in Adobe After Effects
Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file.
local
low complexity
adobe CWE-476
5.5
2021-11-18 CVE-2021-42268 NULL Pointer Dereference vulnerability in Adobe Animate
Adobe Animate version 21.0.9 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted FLA file.
local
low complexity
adobe CWE-476
5.5
2021-10-15 CVE-2021-39864 Cross-Site Request Forgery (CSRF) vulnerability in Adobe Commerce and Magento Open Source
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link.
network
low complexity
adobe CWE-352
6.5
2021-10-15 CVE-2021-40721 Cross-site Scripting vulnerability in Adobe Connect
Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
network
low complexity
adobe CWE-79
6.1
2021-10-13 CVE-2021-40732 NULL Pointer Dereference vulnerability in multiple products
XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the current user.
local
low complexity
adobe debian CWE-476
6.1
2021-09-29 CVE-2021-39845 Stack-based Buffer Overflow vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the current user.
local
low complexity
adobe CWE-121
6.1
2021-09-29 CVE-2021-39846 Out-of-bounds Write vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the current user.
local
low complexity
adobe CWE-787
6.1
2021-09-29 CVE-2021-39849 NULL Pointer Dereference vulnerability in Adobe products
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability.
local
low complexity
adobe CWE-476
5.5