Vulnerabilities > Adobe > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-12 CVE-2021-21080 Cross-site Scripting vulnerability in Adobe Connect
Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
network
low complexity
adobe CWE-79
6.1
2021-03-12 CVE-2021-21079 Cross-site Scripting vulnerability in Adobe Connect
Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
network
low complexity
adobe CWE-79
6.1
2021-03-12 CVE-2021-21078 Untrusted Search Path vulnerability in Adobe Creative Cloud Desktop Application
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an attacker to achieve arbitrary code execution in the process of the current user.
local
low complexity
adobe CWE-426
6.5
2021-03-12 CVE-2021-21068 Creation of Temporary File in Directory with Incorrect Permissions vulnerability in Adobe Creative Cloud Desktop Application
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a file handling vulnerability that could allow an attacker to cause arbitrary file overwriting.
low complexity
adobe CWE-379
6.1
2021-02-23 CVE-2020-29075 Information Exposure vulnerability in Adobe products
Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt.
network
adobe CWE-200
4.3
2021-02-11 CVE-2021-21060 Improper Input Validation vulnerability in Adobe products
Adobe Acrobat Pro DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an improper input validation vulnerability.
network
adobe CWE-20
4.3
2021-02-11 CVE-2021-21057 NULL Pointer Dereference vulnerability in Adobe products
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a null pointer dereference vulnerability when parsing a specially crafted PDF file.
network
adobe CWE-476
4.3
2021-02-11 CVE-2021-21042 Out-of-bounds Read vulnerability in Adobe products
Acrobat Reader DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to arbitrary disclosure of information in the memory stack.
network
low complexity
adobe CWE-125
6.5
2021-02-11 CVE-2021-21041 Use After Free vulnerability in Adobe products
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a use-after-free vulnerability.
network
adobe CWE-416
6.8
2021-02-11 CVE-2021-21040 Use After Free vulnerability in Adobe products
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Use After Free vulnerability.
network
adobe CWE-416
6.8