Adobe Vulnerabilities and Affected Products
Vulnerabilities associated with FrameMaker.
Products
Clear product- Adobe Experience Manager1,018 vulnerabilities
- Adobe Acrobat and Reader516 vulnerabilities
- Acrobat Reader447 vulnerabilities
- Adobe Commerce190 vulnerabilities
- ColdFusion149 vulnerabilities
- Illustrator149 vulnerabilities
- InDesign Desktop131 vulnerabilities
- After Effects119 vulnerabilities
- Dimension116 vulnerabilities
- Bridge114 vulnerabilities
- Animate101 vulnerabilities
- Experience Manager98 vulnerabilities
- InDesign96 vulnerabilities
- Substance3D - Stager87 vulnerabilities
- Magento Commerce85 vulnerabilities
- Adobe Framemaker82 vulnerabilities
- experience_manager78 vulnerabilities
- Substance3D - Painter78 vulnerabilities
- Flash Player70 vulnerabilities
- InCopy65 vulnerabilities
- Photoshop58 vulnerabilities
- experience_manager_cloud_service53 vulnerabilities
- acrobat_reader49 vulnerabilities
- FrameMaker48 vulnerabilities
- acrobat_reader_dc47 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-47425HIGH | Adobe Framemaker | Integer Underflow (Wrap or Wraparound) (CWE-191)Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-191Oct 9, 2024 | CVSS7.8v3.1 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47423HIGH | Adobe Framemaker | Unrestricted Upload of File with Dangerous Type (CWE-434)Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which can be automatically processed or executed by the system. Exploitation of this issue requires user interaction. CWE-434Oct 9, 2024 | CVSS7.8v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47421HIGH | Adobe Framemaker | Out-of-bounds Read (CWE-125)Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Oct 9, 2024 | CVSS7.8v3.1 | EPSS0.367% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47424HIGH | Adobe Framemaker | Integer Overflow or Wraparound (CWE-190)Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-190Oct 9, 2024 | CVSS7.8v3.1 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47422HIGH | Adobe Framemaker | Untrusted Search Path (CWE-426)Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories, which the application could unknowingly execute. This could allow the attacker to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction. CWE-426Oct 9, 2024 | CVSS7.8v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30291HIGH | Adobe FrameMaker TIF File parsing Out Of Bound WriteAdobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787May 16, 2024 | CVSS7.8v3.1 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30292HIGH | Adobe FrameMaker GIF File parsing Out Of Bound WriteAdobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787May 16, 2024 | CVSS7.8v3.1 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30283MEDIUM | Adobe FrameMaker ICO File Parsing Heap Memory CorruptionAdobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125May 16, 2024 | CVSS5.5v3.1 | EPSS0.228% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30290HIGH | Adobe FrameMaker WEBP File Parsing Out Of Bound WriteAdobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787May 16, 2024 | CVSS7.8v3.1 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30286MEDIUM | Adobe FrameMaker DOC File Parsing Memory CorruptionAdobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125May 16, 2024 | CVSS5.5v3.1 | EPSS0.228% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30288HIGH | Adobe FrameMaker 3DS File Parsing Heap Memory CorruptionAdobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS7.8v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30289HIGH | Adobe FrameMaker XLS File Parsing Buffer OverflowAdobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS7.8v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30287MEDIUM | Adobe FrameMaker PDF File Pparsing Out of Bound ReadAdobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125May 16, 2024 | CVSS5.5v3.1 | EPSS0.228% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21621HIGH | Adobe FrameMaker Improper Input Validation Remote Code Execution VulnerabilityFrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-20Feb 17, 2023 | CVSS7.8v3.1 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21619HIGH | Adobe FrameMaker Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityFrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Feb 17, 2023 | CVSS7.8v3.1 | EPSS0.302% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21620MEDIUM | Adobe FrameMaker Font Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityFrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Feb 17, 2023 | CVSS5.5v3.1 | EPSS0.325% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21584MEDIUM | Adobe FrameMaker Font Parsing Use-After-Free Information Disclosure VulnerabilityFrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Feb 17, 2023 | CVSS5.5v3.1 | EPSS0.357% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21622HIGH | Adobe FrameMaker Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityFrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Feb 17, 2023 | CVSS7.8v3.1 | EPSS0.302% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35676HIGH | Adobe FrameMaker SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityAdobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-122Aug 11, 2022 | CVSS7.8v3.1 | EPSS0.513% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-34264MEDIUM | Adobe FrameMaker Font Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityAdobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Aug 11, 2022 | CVSS5.5v3.1 | EPSS0.371% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35673HIGH | Adobe FrameMaker SVG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityAdobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Aug 11, 2022 | CVSS7.8v3.1 | EPSS0.415% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35674HIGH | Adobe FrameMaker SVG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityAdobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Aug 11, 2022 | CVSS7.8v3.1 | EPSS0.415% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35677HIGH | Adobe FrameMaker SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityAdobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-122Aug 11, 2022 | CVSS7.8v3.1 | EPSS0.513% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35675HIGH | Adobe FrameMaker SVG File Parsing Use-After-Free Remote Code Execution VulnerabilityAdobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Aug 11, 2022 | CVSS7.8v3.1 | EPSS0.455% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-28830MEDIUM | Adobe FrameMaker Font Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityAdobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125May 13, 2022 | CVSS5.5v3.1 | EPSS1.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |