← Vulnerability feed

Vulnerability record · CVE-2018-12823 · published 17 October 2018

CVE-2018-12823: Adobe digital editions out-of-bounds write vulnerability

Adobe · Digital Editions

Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

9.8 CVSS 3.0 Critical EPSS 8.3% · top 5.3% CWE-787 · Out-of-bounds write
9.8CVSS 3.0 base score, v2 10.0
8.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-12823 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2017-3088Adobe digital editions memory buffer overflow vulnerabilityAdobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF runtime engine. Successful exploitat…EPSS 6.2%10.0CVE-2014-0494Adobe digital editions memory buffer overflow vulnerabilityAdobe Digital Editions 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via un…EPSS 4.8%10.0CVE-2013-1377Adobe digital editions memory buffer overflow vulnerabilityAdobe Digital Editions 2.x before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified v…EPSS 3.8%9.8CVE-2020-3760Adobe digital editions command injection vulnerabilityAdobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code executi…EPSS 7.1%9.8CVE-2019-7095Adobe digital editions out-of-bounds write vulnerabilityAdobe Digital Editions versions 4.5.10.185749 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code exec…EPSS 9.1%9.8CVE-2018-12813Adobe digital editions out-of-bounds write vulnerabilityAdobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.EPSS 11%9.8CVE-2018-12814Adobe digital editions out-of-bounds write vulnerabilityAdobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.EPSS 11%9.8CVE-2018-12822Adobe digital editions use after free vulnerabilityAdobe Digital Editions versions 4.5.8 and below have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.EPSS 8.0%

Source: NIST National Vulnerability Database (record CVE-2018-12823), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.