Adobe Vulnerabilities and Affected Products
Vulnerabilities associated with Photoshop.
Products
Clear product- Adobe Experience Manager1,018 vulnerabilities
- Adobe Acrobat and Reader516 vulnerabilities
- Acrobat Reader447 vulnerabilities
- Adobe Commerce190 vulnerabilities
- ColdFusion149 vulnerabilities
- Illustrator149 vulnerabilities
- InDesign Desktop131 vulnerabilities
- After Effects119 vulnerabilities
- Dimension116 vulnerabilities
- Bridge114 vulnerabilities
- Animate101 vulnerabilities
- Experience Manager98 vulnerabilities
- InDesign96 vulnerabilities
- Substance3D - Stager87 vulnerabilities
- Magento Commerce85 vulnerabilities
- Adobe Framemaker82 vulnerabilities
- experience_manager78 vulnerabilities
- Substance3D - Painter78 vulnerabilities
- Flash Player70 vulnerabilities
- InCopy65 vulnerabilities
- Photoshop58 vulnerabilities
- experience_manager_cloud_service53 vulnerabilities
- acrobat_reader49 vulnerabilities
- FrameMaker48 vulnerabilities
- acrobat_reader_dc47 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-43760HIGH | Photoshop Desktop | Out-of-bounds Write (CWE-787)Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Sep 13, 2024 | CVSS7.8v3.1 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45109HIGH | Photoshop Desktop | Out-of-bounds Write (CWE-787)Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Sep 13, 2024 | CVSS7.8v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43756HIGH | Photoshop Desktop | Heap-based Buffer Overflow (CWE-122)Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS7.8v3.1 | EPSS0.398% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45108HIGH | Photoshop Desktop | Out-of-bounds Write (CWE-787)Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Sep 13, 2024 | CVSS7.8v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34117HIGH | Adobe Photoshop 2024 MPO File Parsing Use-After-Free vulnerabilityPhotoshop Desktop versions 24.7.3, 25.9.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Aug 14, 2024 | CVSS7.8v3.1 | EPSS0.436% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-20753HIGH | Adobe Photoshop PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityPhotoshop Desktop versions 24.7.3, 25.7 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Jun 13, 2024 | CVSS7.8v3.1 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-20770MEDIUM | Adobe Photoshop 2024 TIF File parsing Out-Of-Bound ReadPhotoshop Desktop versions 24.7.2, 25.3.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Apr 10, 2024 | CVSS5.5v3.1 | EPSS0.337% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-25908HIGH | Adobe Photoshop SVG file Use After Free Arbitrary code executionAdobe Photoshop versions 23.5.3 (and earlier) and 24.1.1 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Mar 27, 2023 | CVSS7.8v3.1 | EPSS0.463% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21578MEDIUM | Adobe Photoshop Font Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityPhotoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Feb 17, 2023 | CVSS5.5v3.1 | EPSS0.325% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21574HIGH | Adobe Photoshop Improper Input Validation Remote Code Execution VulnerabilityPhotoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-20Feb 17, 2023 | CVSS7.8v3.1 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21577MEDIUM | Adobe Photoshop Font Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityPhotoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Feb 17, 2023 | CVSS5.5v3.1 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21576HIGH | Adobe Photoshop Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityPhotoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Feb 17, 2023 | CVSS7.8v3.1 | EPSS0.302% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21575HIGH | Adobe Photoshop Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityPhotoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Feb 17, 2023 | CVSS7.8v3.1 | EPSS0.302% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38434HIGH | Adobe Photoshop SVG File Parsing Use-After-Free Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Sep 16, 2022 | CVSS7.8v3.1 | EPSS0.542% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38432HIGH | Adobe Photoshop SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS7.8v3.1 | EPSS0.587% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38433HIGH | Adobe Photoshop SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.sue requires user interaction in that a victim must open a malicious file. | CVSS7.8v3.1 | EPSS0.475% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38426HIGH | Adobe Photoshop U3D File Parsing Uninitialized Variable Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-824Sep 16, 2022 | CVSS7.8v3.1 | EPSS0.49% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38428MEDIUM | Adobe Photoshop DCM File Parsing Use-After-Free Information Disclosure VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Sep 16, 2022 | CVSS5.5v3.1 | EPSS0.457% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38429HIGH | Adobe Photoshop SVG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Sep 16, 2022 | CVSS7.8v3.1 | EPSS0.483% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38431HIGH | Adobe Photoshop SVG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Sep 16, 2022 | CVSS7.8v3.1 | EPSS0.485% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35713HIGH | Adobe Photoshop U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-787Sep 16, 2022 | CVSS7.8v3.1 | EPSS0.338% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38427HIGH | Adobe Photoshop U3D File Parsing Uninitialized Variable Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-824Sep 16, 2022 | CVSS7.8v3.1 | EPSS0.49% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38430HIGH | Adobe Photoshop MP4 File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-125Sep 16, 2022 | CVSS7.8v3.1 | EPSS0.483% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-34243HIGH | Adobe Photoshop U3D File Parsing Use-After-Free Remote Code Execution VulnerabilityAdobe Photoshop versions 22.5.7 (and earlier) and 23.3.2 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-416Jul 15, 2022 | CVSS7.8v3.1 | EPSS0.509% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-34244MEDIUM | Adobe Photoshop U3D File Parsing Access of Uninitialized Pointer Information Disclosure VulnerabilityAdobe Photoshop versions 22.5.7 (and earlier) and 23.3.2 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CWE-824Jul 15, 2022 | CVSS5.5v3.1 | EPSS0.415% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |