Vulnerability index

Browse CVEs

6,387 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Adobe Air MEDIUM 6.8
CVE-2008-5108

Unspecified vulnerability in Adobe AIR 1.1 and earlier allows context-dependent attackers to execute untrusted JavaScript in an AIR application via u…

Fix: after 1.1
Fix from $1,600 2008-11-17
Coldfusion HIGH 7.2
CVE-2008-4831

Unspecified vulnerability in Adobe ColdFusion 8 and 8.0.1 and ColdFusion MX 7.0.2 allows local users to bypass sandbox restrictions, and obtain sensi…

Patch available
Fix from $1,950 2008-11-10
Acrobat HIGH 9.3
CVE-2008-4812EPSS 9%

Array index error in Adobe Reader and Acrobat, and the Explorer extension (aka AcroRd32Info), 8.1.2, 8.1.1, and earlier allows remote attackers to ex…

Fix: after 8.1.2
Fix from $1,950 2008-11-05
Acrobat HIGH 9.3
CVE-2008-4813EPSS 9%

Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allow remote attackers to execute arbitrary code via a crafted PDF document that (1) pe…

Fix: after 8.1.2
Fix from $1,950 2008-11-05
Acrobat HIGH 9.3
CVE-2008-4814EPSS 12%

Unspecified vulnerability in a JavaScript method in Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allows remote attackers to execute …

Fix: after 8.1.2
Fix from $1,950 2008-11-05
Acrobat HIGH 9.3
CVE-2008-4817EPSS 9%

The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF d…

Fix: after 8.1.2
Fix from $1,950 2008-11-05
Acrobat HIGH 7.5
CVE-2008-4815EPSS 8%

Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan …

Fix: after 8.1.2
Fix from $1,950 2008-11-05
Acrobat HIGH 7.8
CVE-2008-2992 KEVEPSS 98%

Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls…

Fix: after 8.1.2
Fix from $1,950 2008-11-04
Pagemaker HIGH 9.3
CVE-2007-6432EPSS 8%

Stack-based buffer overflow in AldFs32.dll in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a m…

Patch available
Fix from $1,950 2008-10-31
Pagemaker HIGH 9.3
CVE-2007-5394EPSS 8%

Stack-based buffer overflow in AldFs32.dll in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .…

Patch available
Fix from $1,950 2008-10-30
Pagemaker HIGH 9.3
CVE-2007-6021EPSS 8%

Heap-based buffer overflow in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .PMD file with a …

Patch available
Fix from $1,950 2008-10-30
Illustrator HIGH 9.3
CVE-2008-3961EPSS 5%

Multiple unspecified vulnerabilities in Adobe Illustrator CS2 on Macintosh allow user-assisted attackers to execute arbitrary code via a crafted AI f…

Mitigation only
Fix from $1,950 2008-09-18
Acrobat MEDIUM 5.0
CVE-2008-4071EPSS 12%

A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a deni…

No fix yet
Fix from $1,600 2008-09-15
Robohelp Server MEDIUM 6.1
CVE-2008-2991EPSS 16%

Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors …

No fix yet
Fix from $1,600 2008-07-09
Acrobat 3d HIGH 10.0
CVE-2008-2641EPSS 24%

Unspecified vulnerability in Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2, allows remote attackers to cause a denial of service …

Patch available
Fix from $1,950 2008-06-25
Acrobat HIGH 9.3
CVE-2008-2042EPSS 5%

The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitr…

Fix: after 8.1.1
Fix from $1,950 2008-05-08
Photoshop HIGH 9.3
CVE-2008-1765EPSS 20%

Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically pr…

Patch available
Fix from $1,950 2008-04-23
Air HIGH 9.3
CVE-2007-6019EPSS 60%

Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified…

Fix: after 9.0.115.0
Fix from $1,950 2008-04-09
Coldfusion HIGH 7.5
CVE-2008-1656

Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these metho…

Patch available
Fix from $1,950 2008-04-09
Flash MEDIUM 6.8
CVE-2008-1201EPSS 20%

Multiple unspecified vulnerabilities in FLA file parsing in Adobe Flash CS3 Professional, Flash Professional 8, and Flash Basic 8 on Windows allow us…

Mitigation only
Fix from $1,600 2008-03-24
Form Client HIGH 9.3
CVE-2007-6253EPSS 7%

Multiple buffer overflows in Adobe Form Designer 5.0 and Form Client 5.0 allow remote attackers to execute arbitrary code via unknown vectors in the …

Patch available
Fix from $1,950 2008-03-12
Coldfusion HIGH 7.5
CVE-2008-1203EPSS 15%

The administrator interface for Adobe ColdFusion 8 and ColdFusion MX7 does not log failed authentication attempts, which makes it easier for remote a…

Patch available
Fix from $1,950 2008-03-12
Coldfusion MEDIUM 5.0
CVE-2008-0644

Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism for applications via uns…

Patch available
Fix from $1,600 2008-03-12
Robohelp MEDIUM 6.1
CVE-2008-0642

Cross-site scripting (XSS) vulnerability in files created by Adobe RoboHelp 6 and 7, possibly involving use of a (1) WebHelp5 (WebHelp5Ext) or (2) Wi…

Patch available
Fix from $1,600 2008-02-15
Connect Enterprise Server HIGH 10.0
CVE-2007-6148EPSS 8%

Use-after-free vulnerability in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allows remote…

Fix: after 6
Fix from $1,950 2008-02-13
Connect Enterprise Server HIGH 10.0
CVE-2007-6149EPSS 12%

Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote at…

Fix: after 6
Fix from $1,950 2008-02-13
Connect Enterprise Server HIGH 10.0
CVE-2007-6431

Unspecified vulnerability in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allows remote attackers to "take co…

Fix: after 6
Fix from $1,950 2008-02-13
Acrobat HIGH 9.3
CVE-2008-0726EPSS 15%

Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSe…

Fix: after 8.1.1
Fix from $1,950 2008-02-12
Acrobat HIGH 9.3
CVE-2007-5663EPSS 13%

Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript…

Fix: after 8.1.1
Fix from $1,950 2008-02-12
Acrobat HIGH 7.8
CVE-2007-5659 KEVEPSS 94%

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arg…

Fix: 8.1.2+
Fix from $1,950 2008-02-12