cbcvebase.

Adobe Illustrator vulnerabilities

178 known vulnerabilities affecting adobe/illustrator.

Total CVEs
178
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH105MEDIUM58LOW1

Vulnerabilities

Page 5 of 9
CVE-2024-30273P3HIGHCVSS 7.8fixed in 27.9.3≥ 28.0, < 28.4+1 more2024-04-11
CVE-2024-30273 [HIGH] CWE-121 CVE-2024-30273: Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerab Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2023-47063P3HIGHCVSS 7.8≥ 27.0, ≤ 27.9v28.0+1 more2023-12-13
CVE-2023-47063 [HIGH] CWE-787 CVE-2023-47063: Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by an out-of-bound Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-27168P3HIGHCVSS 7.8≥ 28.0, < 28.7.5≥ 29.0, < 29.3+1 more2025-03-11
CVE-2025-27168 [HIGH] CWE-121 CVE-2025-27168: Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a Stack-based Buffer Overflow vulner Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-30641P3HIGHCVSS 7.8≤ 25.4.5≥ 26.0, ≤ 26.0.22023-09-07
CVE-2022-30641 [HIGH] CWE-787 CVE-2022-30641: Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-b Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49531P3HIGHCVSS 7.8≥ 28.0, < 28.7.8≥ 29.0, < 29.6+1 more2025-07-08
CVE-2025-49531 [HIGH] CWE-190 CVE-2025-49531: Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Integer Overflow or Wraparound vu Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-49532P3HIGHCVSS 7.8≥ 28.0, < 28.7.8≥ 29.0, < 29.6+1 more2025-07-08
CVE-2025-49532 [HIGH] CWE-191 CVE-2025-49532: Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Integer Underflow (Wrap or Wrapar Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2008-3961P3CRITICALCVSS 9.3vcs22008-09-18
CVE-2008-3961 [CRITICAL] CVE-2008-3961: Multiple unspecified vulnerabilities in Adobe Illustrator CS2 on Macintosh allow user-assisted attac Multiple unspecified vulnerabilities in Adobe Illustrator CS2 on Macintosh allow user-assisted attackers to execute arbitrary code via a crafted AI file.
nvd
CVE-2021-28592P3HIGHCVSS 7.8≤ 25.2.3≥ unspecified, ≤ 25.2.32021-08-20
CVE-2021-28592 [HIGH] CWE-787 CVE-2021-28592: Adobe Illustrator version 25.2.3 (and earlier) is affected by an Out-of-bounds Write vulnerability w Adobe Illustrator version 25.2.3 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a
nvd
CVE-2021-28591P3HIGHCVSS 7.8≤ 25.2.3≥ unspecified, ≤ 25.2.32021-08-20
CVE-2021-28591 [HIGH] CWE-787 CVE-2021-28591: Adobe Illustrator version 25.2.3 (and earlier) is affected by an Out-of-bounds Write vulnerability w Adobe Illustrator version 25.2.3 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a
nvd
CVE-2022-30644P3HIGHCVSS 7.8≤ 25.4.5≥ 26.0, ≤ 26.0.22023-09-07
CVE-2022-30644 [HIGH] CWE-416 CVE-2022-30644: Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-34263P3HIGHCVSS 7.8≤ 25.4.6≥ 26.0, ≤ 26.3.1+1 more2022-08-11
CVE-2022-34263 [HIGH] CWE-416 CVE-2022-34263: Adobe Illustrator versions 26.3.1 (and earlier) and 25.4.6 (and earlier) are affected by a Use After Adobe Illustrator versions 26.3.1 (and earlier) and 25.4.6 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-41856P3HIGHCVSS 7.8≥ 27.0, < 27.9.5≥ 28.0, < 28.6+1 more2024-08-14
CVE-2024-41856 [HIGH] CWE-20 CVE-2024-41856: Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Valida Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-34260P3HIGHCVSS 7.8≥ 25.0, ≤ 25.4.6≥ 26.0, ≤ 26.3.1+1 more2022-08-11
CVE-2022-34260 [HIGH] CWE-787 CVE-2022-34260: Adobe Illustrator versions 26.3.1 (and earlier) and 25.4.6 (and earlier) are affected by an out-of-b Adobe Illustrator versions 26.3.1 (and earlier) and 25.4.6 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-47450P3HIGHCVSS 7.8fixed in 28.7.2≤ 28.7.12024-11-12
CVE-2024-47450 [HIGH] CWE-122 CVE-2024-47450: Illustrator versions 28.7.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability t Illustrator versions 28.7.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2023-25861P3HIGHCVSS 7.8≤ 26.5.2≥ 27.0.0, < 27.3.1+1 more2023-03-22
CVE-2023-25861 [HIGH] CWE-787 CVE-2023-25861: Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds w Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2023-25860P3HIGHCVSS 7.8≤ 26.5.2≥ 27.0.0, < 27.3.1+1 more2023-03-22
CVE-2023-25860 [HIGH] CWE-787 CVE-2023-25860: Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds w Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2020-24412P3HIGHCVSS 7.8≤ 24.1.2≥ unspecified, ≤ 24.1.22020-10-20
CVE-2020-24412 [HIGH] CWE-788 CVE-2020-24412: Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd
CVE-2020-24413P3HIGHCVSS 7.8≤ 24.1.2≥ unspecified, ≤ 24.1.22020-10-20
CVE-2020-24413 [HIGH] CWE-788 CVE-2020-24413: Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd
CVE-2020-24414P3HIGHCVSS 7.8≤ 24.2≥ unspecified, ≤ 24.1.22020-10-20
CVE-2020-24414 [HIGH] CWE-788 CVE-2020-24414: Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd
CVE-2020-24415P3HIGHCVSS 7.8≤ 24.2≥ unspecified, ≤ 24.1.22020-10-20
CVE-2020-24415 [HIGH] CWE-788 CVE-2020-24415: Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd
Adobe Illustrator vulnerabilities | cvebase