Adobe Indesign vulnerabilities
202 known vulnerabilities affecting adobe/indesign.
Total CVEs
202
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH123MEDIUM75LOW1
Vulnerabilities
Page 10 of 11
CVE-2020-24421P4MEDIUMCVSS 5.5≤ 15.1.2≥ unspecified, ≤ 15.1.22020-10-21
CVE-2020-24421 [MEDIUM] CWE-476 CVE-2020-24421: Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occur
Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. The impact is limited to causing a denial-of-service of the client application. User interaction is required to exploit this issue.
nvd
CVE-2023-47076P4MEDIUMCVSS 5.5≥ 17.0, ≤ 17.4.2v19.02023-12-13
CVE-2023-47076 [MEDIUM] CWE-476 CVE-2023-47076: Adobe InDesign versions 19.0 (and earlier) and 17.4.2 (and earlier) are affected by a NULL Pointer D
Adobe InDesign versions 19.0 (and earlier) and 17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m
nvd
CVE-2026-21358P4MEDIUMCVSS 5.5fixed in 20.5.2≥ 21.0, < 21.22026-02-10
CVE-2026-21358 [MEDIUM] CWE-122 CVE-2026-21358: InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vuln
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a mali
nvd
CVE-2023-44347P4MEDIUMCVSS 5.5≤ 17.4.2≥ 18.0, < 18.5.12024-02-29
CVE-2023-44347 [MEDIUM] CWE-476 CVE-2023-44347: Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Point
Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open
nvd
CVE-2023-44341P4MEDIUMCVSS 5.5≤ 17.4.2≥ 18.0, < 18.5.12024-02-29
CVE-2023-44341 [MEDIUM] CWE-476 CVE-2023-44341: Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Point
Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open
nvd
CVE-2026-27285P4MEDIUMCVSS 5.5fixed in 20.5.3≥ 21.0, < 21.32026-04-14
CVE-2026-27285 [MEDIUM] CWE-122 CVE-2026-27285: InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vuln
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or disrupt its functionality. Exploitation of this issue requires user interaction in that a victim must open a malicious
nvd
CVE-2023-21593P4MEDIUMCVSS 5.5≥ 17.0, ≤ 17.4v18.0+2 more2023-02-17
CVE-2023-21593 [MEDIUM] CWE-476 CVE-2023-21593: Adobe InDesign versions ID18.1 (and earlier) and ID17.4 (and earlier) are affected by a NULL Pointer
Adobe InDesign versions ID18.1 (and earlier) and ID17.4 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a
nvd
CVE-2024-39395P4MEDIUMCVSS 5.5fixed in 18.5.3≥ 19.0, < 19.52024-08-14
CVE-2024-39395 [MEDIUM] CWE-476 CVE-2024-39395: InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a NULL Pointer Dereference vu
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a DoS condition. Exploitation of this issue requires user interaction in that a victim must open
nvd
CVE-2025-30321P4MEDIUMCVSS 5.5fixed in 19.5.4≥ 20.0, < 20.32025-06-10
CVE-2025-30321 [MEDIUM] CWE-476 CVE-2025-30321: InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vu
InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malic
nvd
CVE-2024-41836P4MEDIUMCVSS 5.5fixed in 18.5.3≥ 19.0, < 19.42024-07-23
CVE-2024-41836 [MEDIUM] CWE-476 CVE-2024-41836: InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vu
InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting in a DoS. Exploitation of this issue requires user interaction in that a victim must open
nvd
CVE-2026-34704P4MEDIUMCVSS 5.5fixed in 20.5.4≥ 21.0, < 21.42026-06-09
CVE-2026-34704 [MEDIUM] CWE-476 CVE-2026-34704: InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulner
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must
nvd
CVE-2026-34703P4MEDIUMCVSS 5.5fixed in 20.5.4≥ 21.0, < 21.42026-06-09
CVE-2026-34703 [MEDIUM] CWE-476 CVE-2026-34703: InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulner
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must
nvd
CVE-2024-53952P4MEDIUMCVSS 5.5≤ 18.5.4≥ 19.0, ≤ 19.52024-12-10
CVE-2024-53952 [MEDIUM] CWE-476 CVE-2024-53952: InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by a NULL Pointer Dereference vu
InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim m
nvd
CVE-2025-21125P4MEDIUMCVSS 5.5fixed in 19.5.2v20.02025-02-11
CVE-2025-21125 [MEDIUM] CWE-476 CVE-2025-21125: InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vu
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim m
nvd
CVE-2025-21126P4MEDIUMCVSS 5.5fixed in 19.5.2v20.02025-02-11
CVE-2025-21126 [MEDIUM] CWE-20 CVE-2025-21126: InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to cause the application to crash, resulting in a denial of service. Exploitation of this issue requires user interaction in that
nvd
CVE-2025-27179P4MEDIUMCVSS 5.5fixed in 19.5.3≥ 20.0, < 20.22025-03-11
CVE-2025-27179 [MEDIUM] CWE-476 CVE-2025-27179: InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vu
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim m
nvd
CVE-2025-27176P4MEDIUMCVSS 5.5fixed in 19.5.3≥ 20.0, < 20.22025-03-11
CVE-2025-27176 [MEDIUM] CWE-476 CVE-2025-27176: InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vu
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim m
nvd
CVE-2025-30320P4MEDIUMCVSS 5.5fixed in 19.5.3≥ 20.0, < 20.32025-05-13
CVE-2025-30320 [MEDIUM] CWE-476 CVE-2025-30320: InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vu
InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malic
nvd
CVE-2025-30319P4MEDIUMCVSS 5.5fixed in 19.5.3≥ 20.0, < 20.32025-05-13
CVE-2025-30319 [MEDIUM] CWE-476 CVE-2025-30319: InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vu
InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2006-0525P4MEDIUMCVSS 4.6vcsvcs32006-02-02
CVE-2006-0525 [MEDIUM] CWE-264 CVE-2006-0525: Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center
Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.
nvd