Vulnerabilities > Adobe > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-10 CVE-2020-9728 Out-of-bounds Write vulnerability in Adobe Indesign
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions).
network
adobe CWE-787
6.8
2020-09-10 CVE-2020-9727 Out-of-bounds Write vulnerability in Adobe Indesign
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions).
network
adobe CWE-787
6.8
2020-09-10 CVE-2020-9726 Out-of-bounds Read vulnerability in Adobe Framemaker
Adobe FrameMaker version 2019.0.6 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations.
network
adobe CWE-125
5.8
2020-09-10 CVE-2020-9725 Out-of-bounds Write vulnerability in Adobe Framemaker
Adobe FrameMaker version 2019.0.6 (and earlier versions) lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer.
network
adobe CWE-787
6.8
2020-09-10 CVE-2020-9743 Cross-site Scripting vulnerability in Adobe Experience Manager
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includes arbitrary HTML code in a parameter value.
network
adobe CWE-79
4.3
2020-09-10 CVE-2020-9733 Improper Privilege Management vulnerability in Adobe Experience Manager
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user.
network
low complexity
adobe CWE-269
5.0
2020-09-10 CVE-2020-9732 Cross-site Scripting vulnerability in Adobe Experience Manager
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component.
network
adobe CWE-79
6.0
2020-08-19 CVE-2020-9724 Improper Privilege Management vulnerability in Adobe Lightroom 9.2.0.10
Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability.
network
adobe CWE-269
6.8
2020-08-19 CVE-2020-9723 Out-of-bounds Read vulnerability in Adobe Acrobat DC
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability.
network
low complexity
adobe CWE-125
5.0
2020-08-19 CVE-2020-9721 Out-of-bounds Read vulnerability in Adobe Acrobat DC
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability.
network
low complexity
adobe CWE-125
5.0