Adobe Illustrator vulnerabilities
178 known vulnerabilities affecting adobe/illustrator.
Total CVEs
178
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH105MEDIUM58LOW1
Vulnerabilities
Page 3 of 9
CVE-2020-24410P3HIGHCVSS 7.8≤ 24.2≥ unspecified, ≤ 24.22020-10-20
CVE-2020-24410 [HIGH] CWE-125 CVE-2020-24410: Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when
Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF files. This could result in a read past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd
CVE-2020-24409P3HIGHCVSS 7.8≤ 24.2≥ unspecified, ≤ 24.22020-10-20
CVE-2020-24409 [HIGH] CWE-125 CVE-2020-24409: Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when
Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF files. This could result in a read past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd
CVE-2020-24411P3HIGHCVSS 7.8≤ 24.2≥ unspecified, ≤ 24.22020-10-20
CVE-2020-24411 [HIGH] CWE-787 CVE-2020-24411: Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds write vulnerability whe
Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds write vulnerability when handling crafted PDF files. This could result in a write past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd
CVE-2012-2042P3CRITICALCVSS 10.0v7.0v8.0+11 more2012-05-24
CVE-2012-2042 [CRITICAL] CVE-2012-2042: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
nvd
CVE-2021-36009P3HIGHCVSS 7.8≤ 25.2.3≥ unspecified, ≤ 25.2.32021-08-20
CVE-2021-36009 [HIGH] CWE-788 CVE-2021-36009: Adobe Illustrator version 25.2.3 (and earlier) is affected by an memory corruption vulnerability whe
Adobe Illustrator version 25.2.3 (and earlier) is affected by an memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m
nvd
CVE-2022-30648P3HIGHCVSS 7.8≤ 25.4.5≥ 26.0, ≤ 26.0.2+1 more2022-06-15
CVE-2022-30648 [HIGH] CWE-416 CVE-2022-30648: Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After
Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-30647P3HIGHCVSS 7.8≤ 25.4.5≥ 26.0, ≤ 26.0.2+1 more2022-06-15
CVE-2022-30647 [HIGH] CWE-416 CVE-2022-30647: Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After
Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-36011P3HIGHCVSS 7.8≤ 25.2.3≥ unspecified, ≤ 25.2.32021-08-20
CVE-2021-36011 [HIGH] CWE-78 CVE-2021-36011: Adobe Illustrator version 25.2.3 (and earlier) is affected by a potential Command injection vulnerab
Adobe Illustrator version 25.2.3 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debugging tool for JavaScript scripts. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires use
nvd
CVE-2025-21159P3HIGHCVSS 7.8≥ 28.0, < 28.7.4≥ 29.0, < 29.2.1+1 more2025-02-11
CVE-2025-21159 [HIGH] CWE-416 CVE-2025-21159: Illustrator versions 29.1, 28.7.3 and earlier are affected by a Use After Free vulnerability that co
Illustrator versions 29.1, 28.7.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-43758P3HIGHCVSS 7.8≥ 27.0.0, < 27.9.6≥ 28.0, < 28.7.1+1 more2024-09-13
CVE-2024-43758 [HIGH] CWE-416 CVE-2024-43758: Illustrator versions 28.6, 27.9.5 and earlier are affected by a Use After Free vulnerability that co
Illustrator versions 28.6, 27.9.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-49538P3HIGHCVSS 7.8fixed in 28.7.3v29.0+1 more2024-12-10
CVE-2024-49538 [HIGH] CWE-787 CVE-2024-49538: Illustrator versions 29.0.0, 28.7.2 and earlier are affected by an out-of-bounds write vulnerability
Illustrator versions 29.0.0, 28.7.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-45114P3HIGHCVSS 7.8fixed in 28.7.2≤ 28.7.12024-11-12
CVE-2024-45114 [HIGH] CWE-787 CVE-2024-45114: Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that co
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-34133P3HIGHCVSS 7.8≥ 27.0.0, < 27.9.5≥ 28.0, < 28.6+1 more2024-08-14
CVE-2024-34133 [HIGH] CWE-787 CVE-2024-34133: Illustrator versions 28.5, 27.9.4 and earlier are affected by an out-of-bounds write vulnerability t
Illustrator versions 28.5, 27.9.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-30271P3HIGHCVSS 7.8fixed in 27.9.3≥ 28.0, < 28.4+1 more2024-04-11
CVE-2024-30271 [HIGH] CWE-787 CVE-2024-30271: Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability t
Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-30272P3HIGHCVSS 7.8fixed in 27.9.3≥ 28.0, < 28.4+1 more2024-04-11
CVE-2024-30272 [HIGH] CWE-787 CVE-2024-30272: Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability t
Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-47452P3HIGHCVSS 7.8fixed in 28.7.2≤ 28.7.12024-11-12
CVE-2024-47452 [HIGH] CWE-787 CVE-2024-47452: Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that co
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-47451P3HIGHCVSS 7.8fixed in 28.7.2≤ 28.7.12024-11-12
CVE-2024-47451 [HIGH] CWE-787 CVE-2024-47451: Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that co
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49527P3HIGHCVSS 7.8≥ 28.0, < 28.7.8≥ 29.0, < 29.6+1 more2025-07-08
CVE-2025-49527 [HIGH] CWE-121 CVE-2025-49527: Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulner
Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49528P3HIGHCVSS 7.8≥ 28.0, < 28.7.8≥ 29.0, < 29.6+1 more2025-07-08
CVE-2025-49528 [HIGH] CWE-121 CVE-2025-49528: Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulner
Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49529P3HIGHCVSS 7.8≥ 28.0, < 28.7.8≥ 29.0, < 29.6+1 more2025-07-08
CVE-2025-49529 [HIGH] CWE-824 CVE-2025-49529: Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Access of Uninitialized Pointer v
Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd