Vulnerability CVE-2019-8101


Published: 2019-08-20

Description:
Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an integer overflow vulnerability. Successful exploitation could lead to information disclosure.

Type:

CWE-190

(Integer Overflow or Wraparound)

Vendor: Adobe
Product: Acrobat dc 
Version:
19.012.20034
19.010.20100
19.010.20099
19.010.20098
19.010.20091
19.010.20069
19.010.20064
19.008.20081
19.008.20080
19.008.20074
19.008.20071
18.011.20063
18.011.20058
18.011.20055
18.011.20040
18.011.20038
18.009.20050
18.009.20044
17.012.20098
17.012.20096
17.012.20095
17.012.20093
17.011.30143
17.011.30142
17.011.30140
17.011.30138
17.011.30127
17.011.30120
17.011.30113
17.011.30110
17.011.30106
17.011.30105
17.011.30102
17.011.30099
17.011.30096
17.011.30080
17.011.30079
17.011.30078
17.011.30070
17.011.30068
17.011.30066
17.011.30065
17.011.30059
17.009.20058
17.009.20044
17.000.0000
15.023.20070
15.023.20056
15.023.20053
15.020.20042
15.020.20039
See more versions on NVD
Product: Acrobat reader dc 
Version:
19.012.20034
19.010.20100
19.010.20099
19.010.20098
19.010.20091
19.010.20069
19.010.20064
19.008.20081
19.008.20080
19.008.20074
19.008.20071
18.011.20063
18.011.20055
18.011.20040
18.011.20038
18.009.20050
18.009.20044
17.012.20098
17.012.20095
17.012.20093
17.011.30142
17.011.30140
17.011.30138
17.011.30127
17.011.30120
17.011.30113
17.011.30110
17.011.30106
17.011.30105
17.011.30102
17.011.30099
17.011.30096
17.011.30080
17.011.30079
17.011.30078
17.011.30070
17.011.30068
17.011.30066
17.011.30065
17.011.30059
17.009.20058
17.009.20044
17.000.0000
15.023.20070
15.023.20056
15.023.20053
15.020.20042
15.020.20039
15.017.20053
See more versions on NVD

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
https://helpx.adobe.com/security/products/acrobat/apsb19-41.html

Related CVE
CVE-2018-19725
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation.
CVE-2019-8075
Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
CVE-2019-8074
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the current user.
CVE-2019-8073
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.
CVE-2019-8072
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
CVE-2019-8076
Adobe application manager installer version 10.0 have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
CVE-2019-8070
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
CVE-2019-8069
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

Copyright 2019, cxsecurity.com

 

Back to Top