CVE-2017-2940
https://notcve.org/view.php?id=CVE-2017-2940
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability when processing JPEG 2000 files. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Acrobat Reader 15.020.20042 y anteriores, 15.006.30244 y anteriores, 11.0.18 y anteriores tienen una vulnerabilidad de corrupción de memoria explotable cuando procesa archivos JPEG 2000. Una explotación satisfactoria podría conducir a la ejecución de código arbitrario. • http://www.securityfocus.com/bid/95345 http://www.securitytracker.com/id/1037574 https://helpx.adobe.com/security/products/acrobat/apsb17-01.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-2955
https://notcve.org/view.php?id=CVE-2017-2955
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Acrobat Reader 15.020.20042 y anteriores, 15.006.30244 y anteriores, 11.0.18 y anteriores tienen una vulnerabilidad de uso después de liberación de memoria explotable en el motor JavaScript. Una explotación satisfactoria podría conducir a la ejecución de código arbitrario. • http://www.securityfocus.com/bid/95343 http://www.securitytracker.com/id/1037574 https://helpx.adobe.com/security/products/acrobat/apsb17-01.html • CWE-416: Use After Free •
CVE-2017-2947
https://notcve.org/view.php?id=CVE-2017-2947
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security bypass vulnerability when manipulating Form Data Format (FDF). Las versiones de Adobe Acrobat Reader 15.020.20042 y anteriores, 15.006.30244 y anteriores, 11.0.18 y anteriores tienen una vulnerabilidad para eludir la seguridad cuando manipulan Form Data Format (FDF). • http://www.securityfocus.com/bid/95348 http://www.securitytracker.com/id/1037574 https://helpx.adobe.com/security/products/acrobat/apsb17-01.html • CWE-20: Improper Input Validation •
CVE-2017-2950 – Adobe Reader DC XFA Layout Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-2950
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the XFA engine, related to layout functionality. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Acrobat Reader 15.020.20042 y anteriores, 15.006.30244 y anteriores, 11.0.18 y anteriores tienen una vulnerabilidad de uso después de liberación de memoria explotable en el motor XFA, relacionado con la funcionalidad de diseño. Una explotación satisfactoria podría conducir a la ejecución de código arbitrario. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Reader DC. • http://www.securityfocus.com/bid/95343 http://www.securitytracker.com/id/1037574 http://www.zerodayinitiative.com/advisories/ZDI-17-021 https://helpx.adobe.com/security/products/acrobat/apsb17-01.html • CWE-416: Use After Free •
CVE-2017-2959 – Adobe Acrobat Pro DC ImageConversion JPEG Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-2959
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the image conversion engine, related to parsing of color profile metadata. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Acrobat Reader 15.020.20042 y anteriores, 15.006.30244 y anteriores, 11.0.18 y anteriores tienen una vulnerabilidad de desbordamiento de memoria dinámica explotable en el motor de conversión de imágenes, relacionado con el análisis de los metadatos de perfil de color. Una explotación satisfactoria podría conducir a la ejecución de código arbitrario. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat Pro DC. • http://www.securityfocus.com/bid/95344 http://www.securitytracker.com/id/1037574 http://www.zerodayinitiative.com/advisories/ZDI-17-023 https://helpx.adobe.com/security/products/acrobat/apsb17-01.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •