Adobe Digital Editions vulnerabilities

71 known vulnerabilities affecting adobe/digital_editions.

Total CVEs
71
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL29HIGH28MEDIUM13LOW1

Vulnerabilities

Page 1 of 4
CVE-2023-21582HIGHCVSS 7.8fixed in 4.5.11.187658≥ unspecified, ≤ 4.5.11.1873032023-04-12
CVE-2023-21582 [HIGH] CWE-787 CVE-2023-21582: Adobe Digital Editions version 4.5.11.187303 (and earlier) is affected by an out-of-bounds write vul Adobe Digital Editions version 4.5.11.187303 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
cvelistv5nvd
CVE-2021-39826HIGHCVSS 8.6≤ 4.5.11.187646≥ unspecified, ≤ 4.5.11.1876462021-09-27
CVE-2021-39826 [HIGH] CWE-78 CVE-2021-39826: Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary command execution vu Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary command execution vulnerability. An authenticated attacker could leverage this vulnerability to execute arbitrary commands. User interaction is required to abuse this vulnerability in that a user must open a maliciously crafted .epub file.
cvelistv5nvd
CVE-2021-39827MEDIUMCVSS 6.5≤ 4.5.11.187646≥ unspecified, ≤ 4.5.11.1876462021-09-27
CVE-2021-39827 [MEDIUM] CWE-379 CVE-2021-39827: Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary file write vulnerabi Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary file write vulnerability in the Digital Editions installer. An authenticated attacker could leverage this vulnerability to write an arbitrary file to the system. User interaction is required before product installation to abuse this vulnerability.
cvelistv5nvd
CVE-2021-39828MEDIUMCVSS 6.5≤ 4.5.11.187646≥ unspecified, ≤ 4.5.11.1876462021-09-27
CVE-2021-39828 [MEDIUM] CWE-379 CVE-2021-39828: Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by a privilege escalation vulnerabil Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by a privilege escalation vulnerability in the Digital Editions installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product installation to abuse this vulnerability.
cvelistv5nvd
CVE-2021-21100HIGHCVSS 7.8≤ 4.5.11.187245≥ unspecified, ≤ 4.5.11.1872452021-04-15
CVE-2021-21100 [HIGH] CWE-379 CVE-2021-21100: Adobe Digital Editions version 4.5.11.187245 (and earlier) is affected by a Privilege Escalation vul Adobe Digital Editions version 4.5.11.187245 (and earlier) is affected by a Privilege Escalation vulnerability during installation. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary file system write in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma
cvelistv5nvd
CVE-2020-3798MEDIUMCVSS 6.5≤ 4.5.11.1872122020-06-26
CVE-2020-3798 [MEDIUM] CVE-2020-3798: Adobe Digital Editions versions 4.5.11.187212 and below have a file enumeration (host or local netwo Adobe Digital Editions versions 4.5.11.187212 and below have a file enumeration (host or local network) vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2020-3760CRITICALCVSS 9.8≤ 4.5.102020-02-13
CVE-2020-3760 [CRITICAL] CWE-77 CVE-2020-3760: Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2020-3759HIGHCVSS 7.5≤ 4.5.102020-02-13
CVE-2020-3759 [HIGH] CVE-2020-3759: Adobe Digital Editions versions 4.5.10 and below have a buffer errors vulnerability. Successful expl Adobe Digital Editions versions 4.5.10 and below have a buffer errors vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2019-7095CRITICALCVSS 9.8≤ 4.5.10.1857492019-05-24
CVE-2019-7095 [CRITICAL] CWE-787 CVE-2019-7095: Adobe Digital Editions versions 4.5.10.185749 and below have a heap overflow vulnerability. Successf Adobe Digital Editions versions 4.5.10.185749 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-12817HIGHCVSS 7.5≤ 4.5.92019-01-18
CVE-2018-12817 [HIGH] CWE-125 CVE-2018-12817: Adobe Digital Editions versions 4.5.9 and below have an out of bounds read vulnerability. Successful Adobe Digital Editions versions 4.5.9 and below have an out of bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-12823CRITICALCVSS 9.8≤ 4.5.82018-10-17
CVE-2018-12823 [CRITICAL] CWE-787 CVE-2018-12823: Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful explo Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-12814CRITICALCVSS 9.8≤ 4.5.82018-10-17
CVE-2018-12814 [CRITICAL] CWE-787 CVE-2018-12814: Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful explo Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-12822CRITICALCVSS 9.8≤ 4.5.82018-10-17
CVE-2018-12822 [CRITICAL] CWE-416 CVE-2018-12822: Adobe Digital Editions versions 4.5.8 and below have an use after free vulnerability. Successful exp Adobe Digital Editions versions 4.5.8 and below have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-12813CRITICALCVSS 9.8≤ 4.5.82018-10-17
CVE-2018-12813 [CRITICAL] CWE-787 CVE-2018-12813: Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful explo Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-12820HIGHCVSS 7.5≤ 4.5.82018-10-17
CVE-2018-12820 [HIGH] CWE-125 CVE-2018-12820: Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-12818HIGHCVSS 7.5≤ 4.5.82018-10-17
CVE-2018-12818 [HIGH] CWE-125 CVE-2018-12818: Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-12816HIGHCVSS 7.5≤ 4.5.82018-10-17
CVE-2018-12816 [HIGH] CWE-125 CVE-2018-12816: Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-12821HIGHCVSS 7.5≤ 4.5.82018-10-17
CVE-2018-12821 [HIGH] CWE-125 CVE-2018-12821: Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-12819HIGHCVSS 7.5≤ 4.5.82018-10-17
CVE-2018-12819 [HIGH] CWE-125 CVE-2018-12819: Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful Adobe Digital Editions versions 4.5.8 and below have an out of bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-4925HIGHCVSS 7.5≤ 4.5.72018-05-19
CVE-2018-4925 [HIGH] CWE-125 CVE-2018-4925: Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd