cbcvebase.

Adobe Illustrator vulnerabilities

178 known vulnerabilities affecting adobe/illustrator.

Total CVEs
178
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH105MEDIUM58LOW1

Vulnerabilities

Page 1 of 9
CVE-2009-4195P2CRITICALCVSS 9.3PoCv13.0.0v14.0.02009-12-04
CVE-2009-4195 [CRITICAL] CWE-119 CVE-2009-4195: Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remot Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated PostScript (.eps) file. NOTE: some of these details are obtained from third party information.
nvd
CVE-2012-0780P3CRITICALCVSS 10.0PoCv7.0v8.0+11 more2012-05-09
CVE-2012-0780 [CRITICAL] CWE-119 CVE-2012-0780: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
nvd
CVE-2007-2365P3CRITICALCVSS 9.3PoCvcs32007-04-30
CVE-2007-2365 [CRITICAL] CWE-119 CVE-2007-2365: Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
nvd
CVE-2010-3152P3CRITICALCVSS 9.3PoCv14.0v15.0.12010-08-27
CVE-2010-3152 [CRITICAL] CVE-2010-3152: Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and pos Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.
nvd
CVE-2007-2244P3CRITICALCVSS 9.3PoCvcs32007-04-25
CVE-2007-2244 [CRITICAL] CWE-119 CVE-2007-2244: Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-a Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.
nvd
CVE-2026-48334P3CRITICALCVSS 9.6≥ 29.0, < 29.8.9≥ 30.0, < 30.62026-07-14
CVE-2026-48334 [CRITICAL] CWE-20 CVE-2026-48334: Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is change
nvd
CVE-2014-0513P3CRITICALCVSS 10.0≤ 16.0.4v16.0.1+4 more2014-05-14
CVE-2014-0513 [CRITICAL] CWE-119 CVE-2014-0513: Stack-based buffer overflow in Adobe Illustrator CS6 before 16.0.5 and 16.2.x before 16.2.2 allows r Stack-based buffer overflow in Adobe Illustrator CS6 before 16.0.5 and 16.2.x before 16.2.2 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2021-21105P3HIGHCVSS 8.8≤ 25.2≥ unspecified, ≤ 25.22021-09-08
CVE-2021-21105 [HIGH] CWE-788 CVE-2021-21105: Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when p Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicio
nvd
CVE-2021-21104P3HIGHCVSS 8.8≤ 25.2≥ unspecified, ≤ 25.22021-09-08
CVE-2021-21104 [HIGH] CWE-788 CVE-2021-21104: Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when p Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-21102P3HIGHCVSS 8.8≤ 25.2≥ unspecified, ≤ 25.22021-06-28
CVE-2021-21102 [HIGH] CWE-22 CVE-2021-21102: Adobe Illustrator version 25.2 (and earlier) is affected by a Path Traversal vulnerability when pars Adobe Illustrator version 25.2 (and earlier) is affected by a Path Traversal vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a maliciou
nvd
CVE-2021-21101P3HIGHCVSS 8.8≤ 25.2≥ unspecified, ≤ 25.22021-06-28
CVE-2021-21101 [HIGH] CWE-787 CVE-2021-21101: Adobe Illustrator version 25.2 (and earlier) is affected by an Out-of-bounds Write vulnerability whe Adobe Illustrator version 25.2 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m
nvd
CVE-2021-21103P3HIGHCVSS 8.8≤ 25.2≥ unspecified, ≤ 25.22021-09-08
CVE-2021-21103 [HIGH] CWE-788 CVE-2021-21103: Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when p Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a
nvd
CVE-2026-21280P3HIGHCVSS 8.6≥ 29.0, < 29.8.4v30.0+1 more2026-01-13
CVE-2026-21280 [HIGH] CWE-426 CVE-2026-21280: Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the
nvd
CVE-2026-21333P3HIGHCVSS 8.6≥ 29.0, < 29.8.5≥ 30.0, < 30.2+1 more2026-03-10
CVE-2026-21333 [HIGH] CWE-426 CVE-2026-21333: Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-48275P3HIGHCVSS 8.6≥ 29.0, < 29.8.9≥ 30.0, < 30.62026-07-14
CVE-2026-48275 [HIGH] CWE-426 CVE-2026-48275: Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary cod Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
nvd
CVE-2009-3952P3CRITICALCVSS 10.0≤ 13.0.3v13.0+3 more2010-01-08
CVE-2009-3952 [CRITICAL] CWE-119 CVE-2009-3952: Buffer overflow in Adobe Illustrator CS3 13.0.3 and earlier and Illustrator CS4 14.0.0 allows attack Buffer overflow in Adobe Illustrator CS3 13.0.3 and earlier and Illustrator CS4 14.0.0 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2026-34618P3HIGHCVSS 7.8≥ 29.0, < 29.8.6≥ 30.0, < 30.3+1 more2026-04-14
CVE-2026-34618 [HIGH] CWE-787 CVE-2026-34618: Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds write vulnerability t Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2012-2024P3CRITICALCVSS 10.0v7.0v8.0+11 more2012-05-09
CVE-2012-2024 [CRITICAL] CVE-2012-2024: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.
nvd
CVE-2012-2026P3CRITICALCVSS 10.0v7.0v8.0+11 more2012-05-09
CVE-2012-2026 [CRITICAL] CVE-2012-2026: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.
nvd
CVE-2012-2023P3CRITICALCVSS 10.0v7.0v8.0+11 more2012-05-09
CVE-2012-2023 [CRITICAL] CVE-2012-2023: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
nvd
Adobe Illustrator vulnerabilities | cvebase