📦 Indesign

by Adobe

🔍 What is Indesign?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21357

HIGH CVSS 7.8 Feb 10, 2026

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability affect...

CVE-2026-21304

HIGH CVSS 7.8 Jan 13, 2026

CVE-2026-21304 is a heap-based buffer overflow vulnerability in Adobe InDesign that could allow attackers to execute arbitrary code when a user opens a malicious file. This affects users of InDesign D...

CVE-2026-21275

HIGH CVSS 7.8 Jan 13, 2026

Adobe InDesign versions 21.0, 19.5.5 and earlier contain an uninitialized pointer access vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects all users r...

CVE-2026-21276

HIGH CVSS 7.8 Jan 13, 2026

Adobe InDesign has an uninitialized pointer access vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users running vulnerable versions of InDesign Des...

CVE-2026-21277

HIGH CVSS 7.8 Jan 13, 2026

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow attackers to execute arbitrary code when a user opens a malicious file. The vulnerability affects InDes...

CVE-2025-61815

HIGH CVSS 7.8 Nov 11, 2025

Adobe InDesign versions 20.5, 19.5.5 and earlier contain a use-after-free vulnerability that could allow attackers to execute arbitrary code when a user opens a malicious file. This affects all users ...

CVE-2025-61824

HIGH CVSS 7.8 Nov 11, 2025

A heap-based buffer overflow vulnerability in Adobe InDesign allows attackers to execute arbitrary code when a user opens a malicious file. This affects users of InDesign Desktop versions 20.5, 19.5.5...

CVE-2025-61832

HIGH CVSS 7.8 Nov 11, 2025

A heap-based buffer overflow vulnerability in Adobe InDesign allows attackers to execute arbitrary code when a user opens a malicious file. This affects users of InDesign Desktop versions 20.5, 19.5.5...

CVE-2025-61814

HIGH CVSS 7.8 Nov 11, 2025

Adobe InDesign versions 20.5, 19.5.5 and earlier contain a use-after-free vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects users of InDesign Des...

CVE-2025-54224

HIGH CVSS 7.8 Aug 12, 2025

Adobe InDesign versions 20.4, 19.5.4 and earlier contain a use-after-free vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects all users running vul...

CVE-2025-54226

HIGH CVSS 7.8 Aug 12, 2025

Adobe InDesign has a use-after-free vulnerability that could allow attackers to execute arbitrary code when a user opens a malicious file. This affects users of InDesign Desktop versions 20.4, 19.5.4 ...

CVE-2025-54210

HIGH CVSS 7.8 Aug 12, 2025

Adobe InDesign versions 20.4, 19.5.4 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects all users running vu...

CVE-2025-54212

HIGH CVSS 7.8 Aug 12, 2025

A heap-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users of InDesign Desktop versions 20.4, 19.5.4 and earlie...

CVE-2025-54206

HIGH CVSS 7.8 Aug 12, 2025

Adobe InDesign has an out-of-bounds write vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects users of InDesign Desktop versions 20.4, 19.5.4 and e...

CVE-2025-54208

HIGH CVSS 7.8 Aug 12, 2025

Adobe InDesign versions 20.4, 19.5.4 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code when a user opens a malicious file. This affects all ...

CVE-2025-43591

HIGH CVSS 7.8 Jul 8, 2025

Adobe InDesign versions 19.5.3 and earlier contain a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code when a user opens a malicious file. This affects all users...

CVE-2025-43594

HIGH CVSS 7.8 Jul 8, 2025

Adobe InDesign versions 19.5.3 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a victim's system when they open a malicious file. This ...

CVE-2025-47134

HIGH CVSS 7.8 Jul 8, 2025

Adobe InDesign versions 19.5.3 and earlier contain a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code when a user opens a malicious file. This affects all users...

CVE-2025-43593

HIGH CVSS 7.8 Jun 10, 2025

Adobe InDesign has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users of InDesign Desktop versions ID20.2, ID19.5.3 and ea...

CVE-2025-43589

HIGH CVSS 7.8 Jun 10, 2025

Adobe InDesign has a use-after-free vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users running vulnerable versions of InDesign on their desktop s...

CVE-2025-30318

HIGH CVSS 7.8 May 13, 2025

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file. Affected users include anyone running vulnerable...

CVE-2025-21157

HIGH CVSS 7.8 Feb 11, 2025

Adobe InDesign has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users of InDesign Desktop versions ID20.0, ID19.5.1 and ea...

CVE-2025-21158

HIGH CVSS 7.8 Feb 11, 2025

An integer underflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users of InDesign Desktop versions ID20.0, ID19.5.1 and earlier. S...

CVE-2025-21123

HIGH CVSS 7.8 Feb 11, 2025

Adobe InDesign has a heap-based buffer overflow vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users running vulnerable versions of InDesign on any...

CVE-2024-49545

HIGH CVSS 7.8 Dec 10, 2024

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on the victim's system. The vulnerability affects users of InDesi...

CVE-2024-49543

HIGH CVSS 7.8 Dec 10, 2024

A stack-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users running vulnerable versions of InDesign Desktop on ...

CVE-2024-49509

HIGH CVSS 7.8 Nov 12, 2024

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability affect...

CVE-2024-49507

HIGH CVSS 7.8 Nov 12, 2024

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on a victim's system. The vulnerability affects users of InDesign...

CVE-2024-41853

HIGH CVSS 7.8 Aug 14, 2024

CVE-2024-41853 is a heap-based buffer overflow vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file. This affects users of InDesign Desktop vers...

CVE-2024-41851

HIGH CVSS 7.8 Aug 14, 2024

This CVE describes an integer overflow vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file. Attackers could exploit this to run code with the v...

CVE-2024-39393

HIGH CVSS 7.8 Aug 14, 2024

This CVE describes an out-of-bounds read vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file. Attackers could exploit this to run code with the...

CVE-2024-39390

HIGH CVSS 7.8 Aug 14, 2024

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file. Attackers could gain full control of the affecte...

CVE-2024-39392

HIGH CVSS 7.8 Aug 2, 2024

A heap-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users of InDesign Desktop versions ID18.5.2, ID19.3 and ea...

CVE-2024-20782

HIGH CVSS 7.8 Jul 9, 2024

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file. Attackers could gain the same privileges as the ...

CVE-2024-20785

HIGH CVSS 7.8 Jul 9, 2024

A heap-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users running vulnerable versions of InDesign Desktop. Suc...

CVE-2022-28831

HIGH CVSS 7.8 Sep 11, 2023

Adobe InDesign versions 17.1 and earlier (macOS/Windows) and 16.4.1 and earlier (macOS/Windows) contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user opens...

CVE-2022-28833

HIGH CVSS 7.8 Sep 11, 2023

Adobe InDesign versions 17.1 and earlier (macOS/Windows) and 16.4.1 and earlier (macOS/Windows) contain an out-of-bounds write vulnerability. When exploited, this allows attackers to execute arbitrary...

CVE-2021-39822

HIGH CVSS 7.8 Jul 20, 2023

Adobe InDesign has an out-of-bounds write vulnerability in BMP file parsing that allows arbitrary code execution when a user opens a malicious BMP file. This affects users running Adobe InDesign versi...

CVE-2023-29308

HIGH CVSS 7.8 Jul 12, 2023

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on a victim's system. The vulnerability affects users running vulnerabl...

CVE-2022-34245

HIGH CVSS 7.8 Jul 15, 2022

Adobe InDesign versions 17.2.1 and earlier (and 16.4.1 and earlier) contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrary code on a victim's system. This r...

CVE-2026-21278

MEDIUM CVSS 5.5 Jan 13, 2026

Adobe InDesign versions 21.0, 19.5.5 and earlier contain an out-of-bounds read vulnerability that could allow attackers to access sensitive information from memory. Users who open malicious InDesign f...

CVE-2025-54228

MEDIUM CVSS 5.5 Aug 12, 2025

Adobe InDesign has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents by tricking users into opening malicious files. This affects InDesign Desktop versio...

CVE-2025-54214

MEDIUM CVSS 5.5 Aug 12, 2025

This CVE describes an out-of-bounds read vulnerability in Adobe InDesign that could allow attackers to read sensitive memory contents. Affected users are those running vulnerable versions of InDesign ...

CVE-2025-47105

MEDIUM CVSS 5.5 Jun 10, 2025

Adobe InDesign has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents when users open malicious files. This could help bypass security mitigations like AS...

CVE-2025-30321

MEDIUM CVSS 5.5 Jun 10, 2025

Adobe InDesign has a NULL pointer dereference vulnerability that allows attackers to cause application crashes via malicious files. Users must open a specially crafted file to trigger the denial-of-se...

CVE-2025-30320

MEDIUM CVSS 5.5 May 13, 2025

Adobe InDesign versions ID19.5.2, ID20.2 and earlier contain a NULL pointer dereference vulnerability that allows attackers to cause denial-of-service by crashing the application. Exploitation require...

CVE-2025-21126

MEDIUM CVSS 5.5 Feb 11, 2025

Adobe InDesign has an improper input validation vulnerability that allows attackers to cause denial-of-service by crashing the application. Users must open a malicious file to trigger the exploit. Thi...

CVE-2025-21124

MEDIUM CVSS 5.5 Feb 11, 2025

Adobe InDesign has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents when users open malicious files. This could help bypass security mitigations like AS...

CVE-2024-53952

MEDIUM CVSS 5.5 Dec 10, 2024

Adobe InDesign has a NULL pointer dereference vulnerability that allows attackers to crash the application by tricking users into opening malicious files. This affects users of InDesign Desktop versio...

CVE-2024-49547

MEDIUM CVSS 5.5 Dec 10, 2024

This CVE describes an out-of-bounds read vulnerability in Adobe InDesign that could allow an attacker to read sensitive memory contents. Exploitation requires a user to open a malicious file, potentia...

CVE-2024-49549

MEDIUM CVSS 5.5 Dec 10, 2024

Adobe InDesign has an out-of-bounds read vulnerability that could allow an attacker to read sensitive memory contents and potentially bypass ASLR protections. This affects users of InDesign Desktop ve...

CVE-2024-49511

MEDIUM CVSS 5.5 Nov 12, 2024

Adobe InDesign has an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents when a user opens a malicious file. This could help bypass security mitigations like...

CVE-2024-41866

MEDIUM CVSS 5.5 Aug 14, 2024

Adobe InDesign has a NULL pointer dereference vulnerability that allows attackers to crash the application by tricking users into opening malicious files. This affects users of InDesign Desktop versio...

CVE-2024-39395

MEDIUM CVSS 5.5 Aug 14, 2024

Adobe InDesign has a NULL pointer dereference vulnerability that allows attackers to crash the application by tricking users into opening malicious files. This affects InDesign Desktop versions ID19.4...

CVE-2024-41836

MEDIUM CVSS 5.5 Jul 23, 2024

This CVE describes a NULL pointer dereference vulnerability in Adobe InDesign that allows attackers to cause a denial-of-service by crashing the application. Users must open a malicious file to trigge...