Adobe Illustrator vulnerabilities
178 known vulnerabilities affecting adobe/illustrator.
Total CVEs
178
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH105MEDIUM58LOW1
Vulnerabilities
Page 6 of 9
CVE-2022-38408P3HIGHCVSS 7.8≥ 25.0, ≤ 25.4.7≥ 26.0, ≤ 26.4+1 more2022-09-16
CVE-2022-38408 [HIGH] CWE-20 CVE-2022-38408: Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper I
Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. requires user interaction in that a victim m
nvd
CVE-2023-26426P3HIGHCVSS 7.8≤ 26.5.2≥ 27.0.0, < 27.3.1+1 more2023-03-22
CVE-2023-26426 [HIGH] CWE-416 CVE-2023-26426: Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by a Use After Free v
Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-20791P3HIGHCVSS 7.8fixed in 27.9.4≥ 28.0, < 28.5+1 more2024-05-16
CVE-2024-20791 [HIGH] CWE-125 CVE-2024-20791: Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability wh
Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction
nvd
CVE-2025-27167P3HIGHCVSS 7.8≥ 28.0, < 28.7.5≥ 29.0, < 29.3+1 more2025-03-11
CVE-2025-27167 [HIGH] CWE-426 CVE-2025-27167: Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerabili
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to locate critical resources such as programs, then an attacker could modify t
nvd
CVE-2022-38436P3HIGHCVSS 7.8≤ 25.4.7≥ 26.0, ≤ 26.4+1 more2022-10-25
CVE-2022-38436 [HIGH] CWE-125 CVE-2022-38436: Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bou
Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue
nvd
CVE-2023-47074P3HIGHCVSS 7.8≥ 27.0, ≤ 27.9v28.0+1 more2023-12-13
CVE-2023-47074 [HIGH] CWE-125 CVE-2023-47074: Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by an out-of-bound
Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue re
nvd
CVE-2022-38435P3HIGHCVSS 7.8≤ 25.4.7≥ 26.0, ≤ 26.4+1 more2022-10-25
CVE-2022-38435 [HIGH] CWE-20 CVE-2022-38435: Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper I
Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2023-25859P3HIGHCVSS 7.8≤ 26.5.2≥ 27.0.0, < 27.3.1+1 more2023-03-22
CVE-2023-25859 [HIGH] CWE-20 CVE-2023-25859: Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an Improper Input
Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2020-9573P3HIGHCVSS 7.8≤ 24.0.22020-06-26
CVE-2020-9573 [HIGH] CWE-787 CVE-2020-9573: Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exp
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2020-9571P3HIGHCVSS 7.8≤ 24.0.22020-06-26
CVE-2020-9571 [HIGH] CWE-787 CVE-2020-9571: Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exp
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2020-9570P3HIGHCVSS 7.8≤ 24.0.22020-06-26
CVE-2020-9570 [HIGH] CWE-787 CVE-2020-9570: Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exp
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2020-9574P3HIGHCVSS 7.8≤ 24.0.22020-06-26
CVE-2020-9574 [HIGH] CWE-787 CVE-2020-9574: Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exp
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2020-9572P3HIGHCVSS 7.8≤ 24.0.22020-06-26
CVE-2020-9572 [HIGH] CWE-787 CVE-2020-9572: Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exp
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2020-9575P3HIGHCVSS 7.8≤ 24.1.22020-06-25
CVE-2020-9575 [HIGH] CWE-787 CVE-2020-9575: Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exp
Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2020-9642P3HIGHCVSS 7.8≤ 24.1.22020-06-25
CVE-2020-9642 [HIGH] CWE-119 CVE-2020-9642: Adobe Illustrator versions 24.1.2 and earlier have a buffer errors vulnerability. Successful exploit
Adobe Illustrator versions 24.1.2 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2020-9640P3HIGHCVSS 7.8≤ 24.1.22020-06-25
CVE-2020-9640 [HIGH] CWE-787 CVE-2020-9640: Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exp
Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2020-9639P3HIGHCVSS 7.8≤ 24.1.22020-06-25
CVE-2020-9639 [HIGH] CWE-787 CVE-2020-9639: Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exp
Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2020-9641P3HIGHCVSS 7.8≤ 24.1.22020-06-25
CVE-2020-9641 [HIGH] CWE-787 CVE-2020-9641: Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exp
Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2021-21007P4HIGHCVSS 7.0≤ 25.0v25.0 and earlier2021-01-13
CVE-2021-21007 [HIGH] CWE-427 CVE-2021-21007: Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that
Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-36008P4MEDIUMCVSS 5.5≤ 25.2.3≥ unspecified, ≤ 25.2.32021-08-20
CVE-2021-36008 [MEDIUM] CWE-416 CVE-2021-36008: Adobe Illustrator version 25.2.3 (and earlier) is affected by an Use-after-free vulnerability when p
Adobe Illustrator version 25.2.3 (and earlier) is affected by an Use-after-free vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to read arbitrary file system information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope
nvd