PatchSiren

Adobe CVE debriefs · Page 17

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Adobe CVE published 2022-03-25

CVE-2010-2861

CVE-2010-2861 is an Adobe ColdFusion directory traversal vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. That KEV listing means defenders should treat affected ColdFusion deployments as a priority and follow Adobe's vendor-directed update guidance without delay. CISA also marks the issue as having known ransomware campaign use, which raises the operational urgency for an [truncated]

Known exploited Adobe CVE published 2022-03-25

CVE-2009-0927

CVE-2009-0927 is listed by CISA as a Known Exploited Vulnerability affecting Adobe Reader and Adobe Acrobat. The available source corpus identifies the issue as a stack-based buffer overflow and directs defenders to apply vendor updates. Because CISA marked it as known exploited, any environment still running vulnerable Adobe Reader or Acrobat builds should treat remediation as urgent.

Known exploited Adobe CVE published 2022-03-07

CVE-2013-0631

CVE-2013-0631 is an Adobe ColdFusion information disclosure vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. That placement means the issue is considered known to be exploited in the wild, so affected ColdFusion deployments should be prioritized for remediation using Adobe’s update guidance. The supplied corpus does not include version ranges, impact depth, or CVSS data, so de [truncated]

Known exploited Adobe CVE published 2022-03-07

CVE-2013-0629

CVE-2013-0629 is listed by CISA in the Known Exploited Vulnerabilities catalog for Adobe ColdFusion. The official CISA entry says to apply updates per vendor instructions, and the KEV record dates the listing to 2022-03-07 with a remediation due date of 2022-09-07. Because it is a known exploited vulnerability, affected ColdFusion deployments should be treated as a priority patch item.

Known exploited Adobe CVE published 2022-03-07

CVE-2013-0625

CVE-2013-0625 is an Adobe ColdFusion authentication bypass vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. That KEV listing means defenders should treat affected ColdFusion deployments as high priority and apply Adobe-recommended updates or mitigations as soon as possible.

Known exploited Adobe CVE published 2022-03-07

CVE-2009-3960

CVE-2009-3960 is an Adobe BlazeDS information disclosure vulnerability that CISA has included in its Known Exploited Vulnerabilities (KEV) catalog. The supplied record also marks it as having known ransomware campaign use. Because KEV inclusion indicates confirmed exploitation risk, BlazeDS deployments should be treated as a remediation priority and validated against vendor-directed updates or mitigations.

Known exploited Adobe CVE published 2022-03-03

CVE-2017-11292

CVE-2017-11292 is an Adobe Flash Player type confusion vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied CISA guidance says the impacted product is end-of-life and should be disconnected if still in use. Because this is a known-exploited issue affecting unsupported software, any remaining Flash Player presence should be treated as urgent legacy risk, not routine patching work.

Known exploited Adobe CVE published 2022-03-03

CVE-2016-7855

CVE-2016-7855 is an Adobe Flash Player use-after-free vulnerability that CISA included in its Known Exploited Vulnerabilities catalog. The supplied CISA record treats Flash Player as end-of-life and says it should be disconnected if still in use. Because this is a KEV-listed issue in legacy software, any remaining exposure should be handled as an urgent decommissioning and containment problem rather than [truncated]

Known exploited Adobe CVE published 2022-03-03

CVE-2016-4117

CVE-2016-4117 is an Adobe Flash Player arbitrary code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. CISA’s guidance for the impacted product is explicit: Flash Player is end-of-life and should be disconnected if still in use. CISA added the entry on 2022-03-03 and set a remediation due date of 2022-03-24.

Known exploited Adobe CVE published 2022-03-03

CVE-2016-1019

CVE-2016-1019 is a known exploited Adobe Flash Player vulnerability labeled by CISA as capable of arbitrary code execution. Because Flash Player is end-of-life, CISA’s guidance is not to rely on patching for remediation if it is still present: disconnect it and remove it from use. CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-03-03 and set a due date of 2022-03-24 for remediation action.

Known exploited Adobe CVE published 2022-03-03

CVE-2015-7645

CVE-2015-7645 is an Adobe Flash Player arbitrary code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied record also marks the issue as associated with known ransomware campaign use. Because Flash Player is end-of-life, CISA’s guidance is to disconnect it if it is still present in your environment.

Known exploited Adobe CVE published 2022-03-03

CVE-2015-5119

CVE-2015-5119 is an Adobe Flash Player use-after-free vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key point is that Flash Player is end-of-life: if it is still present anywhere, it should not be treated as a routine patch candidate but as a product to remove or disconnect.

Known exploited Adobe CVE published 2022-03-03

CVE-2015-3043

CVE-2015-3043 is an Adobe Flash Player memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because the impacted product is end-of-life, CISA’s guidance is to disconnect it if it is still in use.

Known exploited Adobe CVE published 2022-03-03

CVE-2014-0496

CVE-2014-0496 affects Adobe Reader and Acrobat and is identified by CISA as a Known Exploited Vulnerability. For defenders, the key takeaway is that this issue was added to the KEV catalog on 2022-03-03 with a remediation due date of 2022-03-24, and CISA’s required action is to apply updates per vendor instructions.

Known exploited Adobe CVE published 2022-03-03

CVE-2013-3346

CVE-2013-3346 is an Adobe Reader and Acrobat memory corruption vulnerability that appears in CISAs Known Exploited Vulnerabilities catalog. Because CISA lists it as known exploited, organizations should treat remediation as a priority and apply vendor updates without delay.

Known exploited Adobe CVE published 2022-03-03

CVE-2013-0641

CVE-2013-0641 is an Adobe Reader buffer overflow vulnerability that CISA included in its Known Exploited Vulnerabilities catalog on 2022-03-03. For defenders, the key signal is not just the vulnerability type but the KEV listing: CISA set a remediation due date of 2022-03-24 and directed organizations to apply vendor updates.

Known exploited Adobe CVE published 2022-03-03

CVE-2013-0640

CVE-2013-0640 is a memory corruption vulnerability in Adobe Reader and Acrobat that CISA lists in its Known Exploited Vulnerabilities catalog. That KEV listing means the issue is confirmed to have been exploited in the wild, so defenders should treat it as a high-priority patching item and apply Adobe updates per vendor instructions.

Known exploited Adobe CVE published 2022-03-03

CVE-2013-0632

CVE-2013-0632 is an Adobe ColdFusion authentication bypass vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. In the supplied timeline, CISA added it on 2022-03-03 and set a remediation due date of 2022-03-24, indicating it should be treated as an actively prioritized security issue for ColdFusion deployments.

Known exploited Adobe CVE published 2022-03-03

CVE-2012-1535

CVE-2012-1535 is an Adobe Flash Player arbitrary code execution vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. Because the impacted product is end-of-life, the practical defensive focus is removal or disconnection rather than patching. Organizations that still have Flash Player present should treat this as a high-priority cleanup item.

Known exploited Adobe CVE published 2022-03-03

CVE-2011-0611

CISA included CVE-2011-0611 in its Known Exploited Vulnerabilities catalog for Adobe Flash Player. The supplied CISA record says the impacted product is end-of-life and should be disconnected if still in use. For defenders, this is a legacy-software exposure that should be treated as urgent because the product is retired and appears in a known-exploitation catalog.

Known exploited Adobe CVE published 2022-03-03

CVE-2010-0188

CVE-2010-0188 is a CISA Known Exploited Vulnerabilities entry affecting Adobe Reader and Acrobat. CISA marks it as a known exploited issue with known ransomware campaign use, so remediation should be treated as urgent for any organization still running affected Adobe software.

Known exploited Adobe CVE published 2022-03-03

CVE-2008-2992

CVE-2008-2992 is an Adobe Acrobat and Reader input validation vulnerability that CISA has included in its Known Exploited Vulnerabilities catalog. The supplied CISA record marks the issue as known to be exploited and notes known ransomware campaign use. Based on the official guidance provided, defenders should prioritize vendor updates and confirm that Acrobat and Reader deployments are fully patched.

Known exploited Adobe CVE published 2022-02-15

CVE-2022-24086

CVE-2022-24086 is an Adobe Commerce and Magento Open Source vulnerability described as improper input validation. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-15, which indicates confirmed exploitation and makes timely remediation important. The official guidance supplied with the KEV entry is to apply updates per vendor instructions.

Known exploited Adobe CVE published 2022-02-15

CVE-2018-15982

CVE-2018-15982 is listed by CISA in the Known Exploited Vulnerabilities catalog as a use-after-free issue in Adobe Flash Player. CISA also marks it as known exploited and notes known ransomware campaign use. Because Flash Player is end-of-life, the recommended defensive action is to disconnect it if it is still present in your environment.

Known exploited Adobe CVE published 2021-11-03

CVE-2021-28550

CVE-2021-28550 is an Adobe Acrobat and Reader use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is KEV-listed, organizations should treat it as a high-priority remediation item and apply Adobe updates according to vendor instructions without delay. CISA’s KEV entry also lists the ransomware-campaign status as unknown, so the main concern [truncated]

Known exploited Adobe CVE published 2021-11-03

CVE-2021-21017

CVE-2021-21017 is a known exploited vulnerability in Adobe Acrobat and Reader described as a heap-based buffer overflow. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and set a remediation due date of 2021-11-17. Organizations and individuals running Acrobat or Reader should prioritize vendor updates.

Known exploited Adobe CVE published 2021-11-03

CVE-2018-4939

CVE-2018-4939 is an Adobe ColdFusion deserialization of untrusted data vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is marked as known exploited, organizations running ColdFusion should treat remediation as a priority and apply vendor-recommended updates.

Known exploited Adobe CVE published 2021-11-03

CVE-2018-4878

CVE-2018-4878 is a use-after-free vulnerability in Adobe Flash Player. CISA lists it in the Known Exploited Vulnerabilities catalog and notes known ransomware campaign use. The CISA record also says the impacted product is end-of-life and should be disconnected if it is still in use.

Known exploited Adobe CVE published 2021-11-03

CVE-2018-15961

CVE-2018-15961 is an Adobe ColdFusion unrestricted file upload vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key signal is confirmed known exploitation: any exposed or unpatched ColdFusion deployment should be treated as a priority remediation item and updated per Adobe’s guidance.

HIGH Adobe CVE published 2017-02-15

CVE-2017-2996

CVE-2017-2996 is a high-severity Adobe Flash Player memory corruption vulnerability in Primetime SDK. Adobe and NVD indicate that versions 24.0.0.194 and earlier are affected, and successful exploitation could lead to arbitrary code execution with user interaction required.