Adobe Photoshop vulnerabilities

93 known vulnerabilities affecting adobe/photoshop.

Total CVEs
93
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH67MEDIUM14LOW2

Vulnerabilities

Page 5 of 5
CVE-2020-9686MEDIUMCVSS 6.5≤ 21.22020-07-22
CVE-2020-9686 [MEDIUM] CWE-125 CVE-2020-9686: Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerabil Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11303CRITICALCVSS 9.8≤ 18.1.12017-12-09
CVE-2017-11303 [CRITICAL] CWE-119 CVE-2017-11303: An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable me An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11304CRITICALCVSS 9.8≤ 18.1.12017-12-09
CVE-2017-11304 [CRITICAL] CWE-416 CVE-2017-11304: An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable us An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable use-after-free vulnerability exists. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2012-2028CRITICALCVSS 9.3v2.5v3.0+21 more2012-05-09
CVE-2012-2028 [CRITICAL] CWE-119 CVE-2012-2028: Buffer overflow in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remo Buffer overflow in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-2027CRITICALCVSS 9.3PoCv2.5v3.0+21 more2012-05-09
CVE-2012-2027 [CRITICAL] CWE-399 CVE-2012-2027: Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1. Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF) file.
nvd
CVE-2011-2131CRITICALCVSS 9.3PoCv12.0v12.12011-08-11
CVE-2011-2131 [CRITICAL] CWE-119 CVE-2011-2131: Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GIF file.
nvd
CVE-2011-2164CRITICALCVSS 10.0≤ 12.0.3v7.0+13 more2011-05-20
CVE-2011-2164 [CRITICAL] CVE-2011-2164: Multiple unspecified vulnerabilities in Adobe Photoshop before 12.0.4 have unknown impact and attack Multiple unspecified vulnerabilities in Adobe Photoshop before 12.0.4 have unknown impact and attack vectors.
nvd
CVE-2010-3127CRITICALCVSS 9.3PoCv9.0v9.0.1+4 more2010-08-26
CVE-2010-3127 [CRITICAL] CVE-2010-3127: Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possi Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop. NOTE: some of these details are obtained
nvd
CVE-2008-1765CRITICALCVSS 9.3PoCv3.22008-04-23
CVE-2008-1765 [CRITICAL] CVE-2008-1765: Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244.
nvd
CVE-2007-2365CRITICALCVSS 9.3PoCv9.0.22007-04-30
CVE-2007-2365 [CRITICAL] CWE-119 CVE-2007-2365: Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
nvd
CVE-2007-2244CRITICALCVSS 9.3PoCv9.0.22007-04-25
CVE-2007-2244 [CRITICAL] CWE-119 CVE-2007-2244: Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-a Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.
nvd
CVE-2006-0525MEDIUMCVSS 4.6v7.0v8.0+2 more2006-02-02
CVE-2006-0525 [MEDIUM] CWE-264 CVE-2006-0525: Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.
nvd
CVE-2005-0151HIGHCVSS 7.5v8.02005-06-13
CVE-2005-0151 [HIGH] CVE-2005-0151: Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Phot Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administrator privileges.
nvd