CVE-2020-24429 – Acrobat Reader DC for macOS Signature Verification Bypass Could Lead to Privilege Escalation
https://notcve.org/view.php?id=CVE-2020-24429
05 Nov 2020 — Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a signature verification bypass that could result in local privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Acrobat Reader DC versiones 2020.012.20048 (y anteriores), 2020.001.30005 (y anteriores) y 2017.011.30175 (y anteriores) para macOS están afectadas por una omisión de verificación de firma... • https://helpx.adobe.com/security/products/acrobat/apsb20-67.html • CWE-347: Improper Verification of Cryptographic Signature •
CVE-2020-24431 – Acrobat Reader DC for macOS Dynamic Library Injection Vulnerability
https://notcve.org/view.php?id=CVE-2020-24431
05 Nov 2020 — Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a security feature bypass that could result in dynamic library code injection by the Adobe Reader process. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Acrobat Reader DC versiones 2020.012.20048 (y anteriores), 2020.001.30005 (y anteriores) y 2017.011.30175 (y anteriores) para macOS están afectadas por una omisió... • https://helpx.adobe.com/security/products/acrobat/apsb20-67.html • CWE-285: Improper Authorization •
CVE-2020-24428 – Acrobat Reader DC for macOS Race Condition Vulnerability Could Lead to Privilege Escalation
https://notcve.org/view.php?id=CVE-2020-24428
05 Nov 2020 — Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a time-of-check time-of-use (TOCTOU) race condition vulnerability that could result in local privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Acrobat Reader DC versiones 2020.012.20048 (y anteriores), 2020.001.30005 (y anteriores) y 2017.011.30175 (y anteriores) para macOS están afectadas por un... • https://helpx.adobe.com/security/products/acrobat/apsb20-67.html • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •
CVE-2020-24437 – Acrobat Reader DC Use-After-Free Vulnerability Could Lead to Arbitrary Code Execution
https://notcve.org/view.php?id=CVE-2020-24437
05 Nov 2020 — Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Acrobat Reader DC versiones 2020.012.20048 (y anteriores), 2020.001.30005 (y anteriores) y 2017.011.30175 (y anteriores) est... • https://helpx.adobe.com/security/products/acrobat/apsb20-67.html • CWE-416: Use After Free •
CVE-2020-24427 – Acrobat Reader DC Codec Input Validation Vulnerability Could Lead to Information Disclosure
https://notcve.org/view.php?id=CVE-2020-24427
05 Nov 2020 — Acrobat Reader versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an input validation vulnerability when decoding a crafted codec that could result in the disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Acrobat Reader versiones 2020.012.20048 (y anteriores), 2020.001.30005 (y anter... • https://helpx.adobe.com/security/products/acrobat/apsb20-67.html • CWE-20: Improper Input Validation •
CVE-2020-24426 – Acrobat Reader DC Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-24426
05 Nov 2020 — Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Acrobat Reader DC versiones 2020.012.20048 (y anteriores), 2020.001.30005 (y anteriores) y 2017.011.30175 (y a... • https://helpx.adobe.com/security/products/acrobat/apsb20-67.html • CWE-125: Out-of-bounds Read •
CVE-2018-4999 – Adobe Acrobat Pro DC EMF Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2018-4999
23 May 2018 — Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.006.30394 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. Adobe Acrobat y Reader en versiones 2018.009.20050 y anteriores, 2017.011.30070 y anteriores y 2015.006.30394 y anteriores tienen una vulnerabilidad de desbordamiento de lectura fuera de límites. Su explotación con éxito podría permitir la ejecución ... • http://www.securityfocus.com/bid/104266 • CWE-125: Out-of-bounds Read •
CVE-2018-4998 – Adobe Acrobat Pro DC HTML2PDF HTML Parsing Memory Corruption Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-4998
23 May 2018 — Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.006.30394 and earlier have a Memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. Adobe Acrobat y Reader en versiones 2018.009.20050 y anteriores, 2017.011.30070 y anteriores y 2015.006.30394 y anteriores tienen una vulnerabilidad de corrupción de memoria. Su explotación con éxito podría permitir la ejecución de código arbitrario en... • http://www.securityfocus.com/bid/104265 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4997 – Adobe Acrobat Pro DC HTML2PDF HTML Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-4997
23 May 2018 — Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.006.30394 and earlier have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. Adobe Acrobat y Reader en versiones 2018.009.20050 y anteriores, 2017.011.30070 y anteriores y 2015.006.30394 y anteriores tienen una vulnerabilidad de desbordamiento de escritura fuera de límites. Su explotación con éxito podría permitir la ejecuci... • http://www.securityfocus.com/bid/104264 • CWE-787: Out-of-bounds Write •
CVE-2017-11308 – Adobe Acrobat Pro DC ImageConversion EMF BMP Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-11308
07 Mar 2018 — Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. Adobe Acrobat y Reader 2017.012.20098 y anteriores, 2017.011.30066 y anteriores, 2015.006.30355 y anteriores, y 11.0.22 y anteriores tiene una vulnerabilidad explotable de desbordamiento de memoria dinámica (heap). Su explotac... • https://helpx.adobe.com/security/products/acrobat/apsb17-36.html • CWE-787: Out-of-bounds Write •