cbcvebase.

Adobe Illustrator vulnerabilities

179 known vulnerabilities affecting adobe/illustrator.

Total CVEs
179
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH105MEDIUM59LOW1

Vulnerabilities

Page 2 of 9
CVE-2012-2025P3CRITICALCVSS 10.0v7.0v8.0+11 more2012-05-09
CVE-2012-2025 [CRITICAL] CVE-2012-2025: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.
nvd
CVE-2026-48337P3HIGHCVSS 7.8≥ 29.0, < 29.8.9≥ 30.0, < 30.62026-07-14
CVE-2026-48337 [HIGH] CWE-787 CVE-2026-48337: Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-48335P3HIGHCVSS 7.8≥ 29.0, < 29.8.9≥ 30.0, < 30.62026-07-14
CVE-2026-48335 [HIGH] CWE-787 CVE-2026-48335: Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-48336P3HIGHCVSS 7.8≥ 29.0, < 29.8.9≥ 30.0, < 30.62026-07-14
CVE-2026-48336 [HIGH] CWE-787 CVE-2026-48336: Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-61831P3HIGHCVSS 7.8≥ 28.0, ≤ 28.7.10≥ 29.0, < 29.8.3+1 more2025-11-11
CVE-2025-61831 [HIGH] CWE-787 CVE-2025-61831: Illustrator versions 28.7.10, 29.8.2 and earlier are affected by an out-of-bounds write vulnerabilit Illustrator versions 28.7.10, 29.8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-34661P3HIGHCVSS 7.8≥ 29.0, < 29.8.7≥ 30.0, < 30.42026-05-12
CVE-2026-34661 [HIGH] CWE-787 CVE-2026-34661: Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability t Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-21362P3HIGHCVSS 7.8≥ 29.0, < 29.8.5≥ 30.0, < 30.22026-03-10
CVE-2026-21362 [HIGH] CWE-787 CVE-2026-21362: Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability t Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-27272P3HIGHCVSS 7.8≥ 29.0, < 29.8.5≥ 30.0, < 30.22026-03-10
CVE-2026-27272 [HIGH] CWE-787 CVE-2026-27272: Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability t Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-23188P3HIGHCVSS 7.8≤ 25.4.3≥ 26.0.0, ≤ 26.0.2+1 more2022-02-16
CVE-2022-23188 [HIGH] CWE-120 CVE-2022-23188: Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a buffer ov Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a buffer overflow vulnerability due to insecure handling of a crafted malicious file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted malicious file i
nvd
CVE-2020-24411P3HIGHCVSS 7.8≤ 24.2≥ unspecified, ≤ 24.22020-10-20
CVE-2020-24411 [HIGH] CWE-787 CVE-2020-24411: Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds write vulnerability whe Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds write vulnerability when handling crafted PDF files. This could result in a write past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd
CVE-2021-21054P3HIGHCVSS 7.8≤ 25.1≥ unspecified, ≤ 25.12021-02-11
CVE-2021-21054 [HIGH] CWE-787 CVE-2021-21054: Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability whe Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious f
nvd
CVE-2012-2042P3CRITICALCVSS 10.0v7.0v8.0+11 more2012-05-24
CVE-2012-2042 [CRITICAL] CVE-2012-2042: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
nvd
CVE-2022-23186P3HIGHCVSS 7.8≤ 25.4.3≥ 26.0.0, ≤ 26.0.2+1 more2022-02-16
CVE-2022-23186 [HIGH] CWE-787 CVE-2022-23186: Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-b Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-30649P3HIGHCVSS 7.8≤ 25.4.5≥ 26.0, ≤ 26.0.2+1 more2022-06-15
CVE-2022-30649 [HIGH] CWE-787 CVE-2022-30649: Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-b Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-61820P3HIGHCVSS 7.8≥ 28.0, ≤ 28.7.10≥ 29.0, < 29.8.3+1 more2025-11-11
CVE-2025-61820 [HIGH] CWE-122 CVE-2025-61820: Illustrator versions 28.7.10, 29.8.2 and earlier are affected by a Heap-based Buffer Overflow vulner Illustrator versions 28.7.10, 29.8.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49563P3HIGHCVSS 7.8≥ 28.0, < 28.7.9≥ 29.0, < 29.7+1 more2025-08-12
CVE-2025-49563 [HIGH] CWE-787 CVE-2025-49563: Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-54283P3HIGHCVSS 7.8≥ 28.0, < 28.7.10≥ 29.0, < 29.8+1 more2025-10-14
CVE-2025-54283 [HIGH] CWE-787 CVE-2025-54283: Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability t Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-54284P3HIGHCVSS 7.8≥ 28.0, < 28.7.10≥ 29.0, < 29.8+1 more2025-10-14
CVE-2025-54284 [HIGH] CWE-787 CVE-2025-54284: Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability t Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-27267P3HIGHCVSS 7.8≥ 29.0, < 29.8.5≥ 30.0, < 30.22026-03-10
CVE-2026-27267 [HIGH] CWE-121 CVE-2026-27267: Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerab Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2020-24410P3HIGHCVSS 7.8≤ 24.2≥ unspecified, ≤ 24.22020-10-20
CVE-2020-24410 [HIGH] CWE-125 CVE-2020-24410: Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF files. This could result in a read past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd