High
CVE-2023-21598 CVSS:5.5
Adobe InCopy could allow a remote attacker to obtain sensitive information, caused by a use-after-free error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVE-2023-21595 CVSS:5.5
Adobe InCopy could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write error. By persuading a victim to open a specially-crafted document, an attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
CVE-2023-21594 CVSS:7.8
Adobe InCopy is vulnerable to a heap-based buffer overflow. By persuading a victim to open a specially-crafted document, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVE-2023-21597 CVSS:7.8
Adobe InCopy could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write error. By persuading a victim to open a specially-crafted document, an attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
CVE-2023-21599 CVSS:5.5
Adobe InCopy could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVE-2023-21596 CVSS:7.8
Adobe InCopy could allow a remote attacker to execute arbitrary code on the system, caused by improper validation of input. By persuading a victim to open a specially-crafted document, an attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
Adobe
Refer to Adobe Security Advisory for patch, upgrade or suggested workaround information.