cbcvebase.

Adobe After Effects vulnerabilities

127 known vulnerabilities affecting adobe/after_effects.

Total CVEs
127
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH86MEDIUM28LOW12

Vulnerabilities

Page 6 of 7
CVE-2024-47444P4MEDIUMCVSS 5.5≤ 23.6.9≥ 24.0, < 24.6.32024-11-12
CVE-2024-47444 [MEDIUM] CWE-125 CVE-2024-47444: After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerabilit After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-47446P4MEDIUMCVSS 5.5≤ 23.6.9≥ 24.0, < 24.6.32024-11-12
CVE-2024-47446 [MEDIUM] CWE-125 CVE-2024-47446: After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerabilit After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43587P4MEDIUMCVSS 5.5fixed in 24.6.7≥ 25.0, < 25.3+1 more2025-07-08
CVE-2025-43587 [MEDIUM] CWE-125 CVE-2025-43587: After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-54240P4MEDIUMCVSS 5.5fixed in 24.6.8≥ 25.0, < 25.4+1 more2025-09-09
CVE-2025-54240 [MEDIUM] CWE-125 CVE-2025-54240: After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-54239P4MEDIUMCVSS 5.5fixed in 24.6.8≥ 25.0, < 25.4+1 more2025-09-09
CVE-2025-54239 [MEDIUM] CWE-125 CVE-2025-54239: After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-54241P4MEDIUMCVSS 5.5fixed in 24.6.8≥ 25.0, < 25.4+1 more2025-09-09
CVE-2025-54241 [MEDIUM] CWE-125 CVE-2025-54241: After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-21319P4MEDIUMCVSS 5.5fixed in 25.6.4≤ 25.62026-02-10
CVE-2026-21319 [MEDIUM] CWE-125 CVE-2026-21319: After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that cou After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2023-22233P4MEDIUMCVSS 5.5≥ 22.0.0, < 22.6.4≥ 23.0.0, < 23.2.0+1 more2023-02-17
CVE-2023-22233 [MEDIUM] CWE-125 CVE-2023-22233: After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds rea After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2020-3809P4MEDIUMCVSS 5.5≤ 17.0.12020-06-26
CVE-2020-3809 [MEDIUM] CWE-125 CVE-2020-3809: Adobe After Effects versions 17.0.1 and earlier have an out-of-bounds read vulnerability. Successful Adobe After Effects versions 17.0.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
nvd
CVE-2021-28601P4MEDIUMCVSS 5.5≤ 18.2≥ unspecified, ≤ 18.22021-08-24
CVE-2021-28601 [MEDIUM] CWE-476 CVE-2021-28601: Adobe After Effects version 18.2 (and earlier) is affected by a Null pointer dereference vulnerabili Adobe After Effects version 18.2 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a vict
nvd
CVE-2021-40756P4MEDIUMCVSS 5.5≤ 18.4.1≥ unspecified, ≤ 18.4.12021-11-18
CVE-2021-40756 [MEDIUM] CWE-476 CVE-2021-40756: Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerabi Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a vi
nvd
CVE-2021-40761P4MEDIUMCVSS 5.5≤ 18.4.1≥ unspecified, ≤ 18.4.12021-11-18
CVE-2021-40761 [MEDIUM] CWE-476 CVE-2021-40761: Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerabi Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a vi
nvd
CVE-2026-21350P4MEDIUMCVSS 5.5fixed in 25.6.4≤ 25.62026-02-10
CVE-2026-21350 [MEDIUM] CWE-476 CVE-2026-21350: After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability tha After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-47109P4MEDIUMCVSS 5.5fixed in 24.6.7≥ 25.0, < 25.3+1 more2025-07-08
CVE-2025-47109 [MEDIUM] CWE-476 CVE-2025-47109: After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerabi After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious f
nvd
CVE-2025-27185P4MEDIUMCVSS 5.5fixed in 24.6.5≥ 25.0, < 25.2+1 more2025-04-08
CVE-2025-27185 [MEDIUM] CWE-476 CVE-2025-27185: After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerabi After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2021-35995P4LOWCVSS 3.3≤ 18.2.1≥ unspecified, ≤ 18.2.12021-09-02
CVE-2021-35995 [LOW] CWE-20 CVE-2021-35995: Adobe After Effects version 18.2.1 (and earlier) is affected by an Improper input validation vulnera Adobe After Effects version 18.2.1 (and earlier) is affected by an Improper input validation vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim
nvd
CVE-2021-36019P4LOWCVSS 3.3≤ 18.2.1≥ unspecified, ≤ 18.2.12021-09-02
CVE-2021-36019 [LOW] CWE-125 CVE-2021-36019: Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op
nvd
CVE-2021-28587P4LOWCVSS 3.3fixed in 18.2≥ unspecified, ≤ 18.02021-06-28
CVE-2021-28587 [LOW] CWE-125 CVE-2021-28587: After Effects versions 18.0 (and earlier) are affected by an out-of-bounds read vulnerability that c After Effects versions 18.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-36018P4LOWCVSS 3.3≤ 18.2.1≥ unspecified, ≤ 18.2.12021-09-02
CVE-2021-36018 [LOW] CWE-125 CVE-2021-36018: Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op
nvd
CVE-2021-44189P4LOWCVSS 3.3≤ 18.4.2≥ 22.0, < 22.1.12023-09-07
CVE-2021-44189 [LOW] CWE-416 CVE-2021-44189: Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Use-Afte Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd