High
CVE-2023-21589 CVSS:7.8
Adobe InDesign could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write error. By persuading a victim to open a specially-crafted document, an attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
CVE-2023-21591 CVSS:5.5
Adobe InDesign could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVE-2023-21592 CVSS:5.5
Adobe InDesign could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVE-2023-21587 CVSS:7.8
Adobe InDesign is vulnerable to a heap-based buffer overflow. By persuading a victim to open a specially-crafted document, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVE-2023-21588 CVSS:7.8
Adobe InDesign could allow a remote attacker to execute arbitrary code on the system, caused by improper validation of input. By persuading a victim to open a specially-crafted document, an attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
CVE-2023-21590 CVSS:7.8
Adobe InDesign could allow a remote attacker to execute arbitrary code on the system, caused by improper validation of input. By persuading a victim to open a specially-crafted document, an attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
Adobe
Refer to Adobe Security Advisory for patch, upgrade or suggested workaround information.