Vulnerability CVE-2011-4373


Published: 2012-01-10   Modified: 2012-02-13

Description:
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4372.

Type:

CWE-noinfo

Vendor: Adobe
Product: Acrobat 
Version:
9.4.7
9.4.6
9.4.5
9.4.4
9.4.3
9.4.2
9.4.1
9.4
9.3.4
9.3.3
9.3.2
9.3.1
9.3
9.2
9.1.3
9.1.2
9.1.1
9.1
9.0
10.1.1
10.1
10.0.3
10.0.2
10.0.1
10.0
Product: Reader 
Version:
9.4.7
9.4.6
9.4.5
9.4.4
9.4.3
9.4.2
9.4.1
9.4
9.3.4
9.3.3
9.3.2
9.3.1
9.3
9.2
9.1.3
9.1.2
9.1.1
9.1
9.0
10.1.1
10.1
10.0.3
10.0.2
10.0.1
10.0
Product: Adobe reader 
Version:
9.3.4
9.3.3
9.3.2
9.3.1
9.3
9.2
Product: Acrobat reader 
Version:
9.1.3
9.1.2
9.1.1
9.1
9.0

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
http://www.adobe.com/support/security/bulletins/apsb12-01.html
http://www.securitytracker.com/id?1026496
http://www.securityfocus.com/bid/51350
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14615

Related CVE
CVE-2017-11305
A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference file when a user clears browser data.
CVE-2017-3114
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region...
CVE-2017-3112
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of...
CVE-2017-3111
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstances.
CVE-2017-3109
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Adobe Experience Manager has a reflected cross-site scripting vulnerability in the HtmlRendererServlet.
CVE-2017-16420
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computati...
CVE-2017-16419
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The issue is a stack exhaustion problem within the J...
CVE-2017-16418
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computati...

Copyright 2018, cxsecurity.com

 

Back to Top