cbcvebase.

Adobe Photoshop vulnerabilities

94 known vulnerabilities affecting adobe/photoshop.

Total CVEs
94
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH68MEDIUM14LOW2

Vulnerabilities

Page 1 of 5
CVE-2011-2131P2CRITICALCVSS 9.3PoCv12.0v12.12011-08-11
CVE-2011-2131 [CRITICAL] CWE-119 CVE-2011-2131: Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GIF file.
nvd
CVE-2012-2027P2CRITICALCVSS 9.3PoCv2.5v3.0+21 more2012-05-09
CVE-2012-2027 [CRITICAL] CWE-399 CVE-2012-2027: Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1. Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF) file.
nvd
CVE-2007-2365P3CRITICALCVSS 9.3PoCv9.0.22007-04-30
CVE-2007-2365 [CRITICAL] CWE-119 CVE-2007-2365: Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
nvd
CVE-2007-2244P3CRITICALCVSS 9.3PoCv9.0.22007-04-25
CVE-2007-2244 [CRITICAL] CWE-119 CVE-2007-2244: Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-a Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.
nvd
CVE-2010-3127P3CRITICALCVSS 9.3PoCv9.0v9.0.1+4 more2010-08-26
CVE-2010-3127 [CRITICAL] CVE-2010-3127: Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possi Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop. NOTE: some of these details are obtained
nvd
CVE-2008-1765P3CRITICALCVSS 9.3PoCv3.22008-04-23
CVE-2008-1765 [CRITICAL] CVE-2008-1765: Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244.
nvd
CVE-2012-2028P3CRITICALCVSS 9.3v2.5v3.0+21 more2012-05-09
CVE-2012-2028 [CRITICAL] CWE-119 CVE-2012-2028: Buffer overflow in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remo Buffer overflow in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2017-11304P3CRITICALCVSS 9.8≤ 18.1.12017-12-09
CVE-2017-11304 [CRITICAL] CWE-416 CVE-2017-11304: An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable us An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable use-after-free vulnerability exists. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11303P3CRITICALCVSS 9.8≤ 18.1.12017-12-09
CVE-2017-11303 [CRITICAL] CWE-119 CVE-2017-11303: An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable me An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2020-9687P3HIGHCVSS 8.8≤ 21.22020-07-22
CVE-2020-9687 [HIGH] CWE-787 CVE-2020-9687: Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerabi Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2020-9685P3HIGHCVSS 8.8≤ 21.22020-07-22
CVE-2020-9685 [HIGH] CWE-787 CVE-2020-9685: Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerabi Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2020-9684P3HIGHCVSS 8.8≤ 21.22020-07-22
CVE-2020-9684 [HIGH] CWE-787 CVE-2020-9684: Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerabi Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
nvd
CVE-2021-21006P3HIGHCVSS 8.6≤ 22.1v22.1 and earlier2021-01-13
CVE-2021-21006 [HIGH] CWE-122 CVE-2021-21006: Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially crafted font file. Successful exploitation could lead to arbitrary code execution. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-21051P3HIGHCVSS 7.8≤ 21.2.4≥ 22.0, ≤ 22.1.1+1 more2021-02-11
CVE-2021-21051 [HIGH] CWE-120 CVE-2021-21051: Adobe Photoshop versions 21.2.4 (and earlier) and 22.1.1 (and earlier) are affected by a Buffer Over Adobe Photoshop versions 21.2.4 (and earlier) and 22.1.1 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted javascript file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti
nvd
CVE-2020-9683P3HIGHCVSS 8.8≤ 21.22020-07-22
CVE-2020-9683 [HIGH] CWE-125 CVE-2020-9683: Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerabil Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2021-28549P3HIGHCVSS 7.8≤ 21.2.6≥ 22.0, ≤ 22.3+1 more2021-04-15
CVE-2021-28549 [HIGH] CWE-120 CVE-2021-28549: Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overfl Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted JSX file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha
nvd
CVE-2021-28548P3HIGHCVSS 7.8≤ 21.2.6≥ 22.0, < 22.3+1 more2021-04-15
CVE-2021-28548 [HIGH] CWE-120 CVE-2021-28548: Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overfl Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted JSX file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha
nvd
CVE-2021-21047P3HIGHCVSS 7.8≤ 21.2.4≥ 22.0, ≤ 22.1.1+1 more2021-02-11
CVE-2021-21047 [HIGH] CWE-787 CVE-2021-21047: Adobe Photoshop versions 21.2.4 (and earlier) and 22.1.1 (and earlier) are affected by an Out-of-bou Adobe Photoshop versions 21.2.4 (and earlier) and 22.1.1 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fi
nvd
CVE-2021-21067P3HIGHCVSS 7.8≥ unspecified, ≤ 22.22021-03-12
CVE-2021-21067 [HIGH] CWE-787 CVE-2021-21067: Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by an Out-of-bound Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by an Out-of-bounds Write vulnerability in the CoolType library. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu
nvd
CVE-2022-28272P3HIGHCVSS 7.8≤ 22.5.6≥ 23.0.0, ≤ 23.2.2+1 more2022-05-06
CVE-2022-28272 [HIGH] CWE-787 CVE-2022-28272: Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bou Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
Adobe Photoshop vulnerabilities | cvebase