CVE-2010-0201
published 2010-04-14CVE-2010-0201: Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or…
PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.89%
91.2th percentile
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0204.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Acroread: Multiple code execution flaws (APSB10-09)
vendor_redhat·2010-04-13·CVSS 9.3
CVE-2010-0204 [CRITICAL] Acroread: Multiple code execution flaws (APSB10-09)
Acroread: Multiple code execution flaws (APSB10-09)
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0201.
Red Hat
Acroread: Multiple code execution flaws (APSB10-09)
vendor_redhat·2010-04-13·CVSS 9.3
CVE-2010-0201 [CRITICAL] Acroread: Multiple code execution flaws (APSB10-09)
Acroread: Multiple code execution flaws (APSB10-09)
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0204.
Red Hat
Acroread: Multiple code execution flaws (APSB10-09)
vendor_redhat·2010-04-13·CVSS 9.3
CVE-2010-0197 [CRITICAL] Acroread: Multiple code execution flaws (APSB10-09)
Acroread: Multiple code execution flaws (APSB10-09)
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0201, and CVE-2010-0204.
Red Hat
Acroread: Multiple code execution flaws (APSB10-09)
vendor_redhat·2010-04-13·CVSS 9.3
CVE-2010-0194 [CRITICAL] Acroread: Multiple code execution flaws (APSB10-09)
Acroread: Multiple code execution flaws (APSB10-09)
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0197, CVE-2010-0201, and CVE-2010-0204.
GHSA
GHSA-w4p3-9jw4-3vwr: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-0194 [CRITICAL] CWE-119 GHSA-w4p3-9jw4-3vwr: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0197, CVE-2010-0201, and CVE-2010-0204.
GHSA
GHSA-jv8c-ggjv-cc68: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-0201 [CRITICAL] CWE-119 GHSA-jv8c-ggjv-cc68: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0204.
GHSA
GHSA-8w8r-x75f-4wvv: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-0197 [CRITICAL] CWE-119 GHSA-8w8r-x75f-4wvv: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0201, and CVE-2010-0204.
GHSA
GHSA-mp5m-jpf6-cg5g: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-0204 [CRITICAL] CWE-119 GHSA-mp5m-jpf6-cg5g: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0201.
Suricata
GPL NETBIOS SMB trans2open buffer overflow attempt
suricata·2010-09-23
CVE-2003-0201 GPL NETBIOS SMB trans2open buffer overflow attempt
GPL NETBIOS SMB trans2open buffer overflow attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB trans2open buffer overflow attempt"; flow:established,to_server; content:"|00|"; depth:1; content:"|FF|SMB2"; depth:5; offset:4; content:"|00 14|"; depth:2; offset:60; byte_test:2,>,256,0,relative,little; reference:bugtraq,7294; reference:cve,2003-0201; reference:url,www.digitaldefense.net/labs/advisories/DDI-1013.txt; classtype:attempted-admin; sid:2102103; rev:11; metadata:created_at 2010_09_23, cve CVE_2003_0201, confidence High, signature_severity Major, updated_at 2024_03_08;)
Exploit-DB
Samba 2.2.8 (Linux x86) - 'trans2open' Remote Overflow (Metasploit)
exploitdb·2010-07-14
CVE-2003-0201 Samba 2.2.8 (Linux x86) - 'trans2open' Remote Overflow (Metasploit)
Samba 2.2.8 (Linux x86) - 'trans2open' Remote Overflow (Metasploit)
---
##
# $Id: trans2open.rb 9828 2010-07-14 17:27:23Z hdm $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Samba trans2open Overflow (Linux x86)',
'Description' => %q{
This exploits the buffer overflow found in Samba versions
2.2.0 to 2.2.8. This particular module is capable of
exploiting the flaw on x86 Linux systems that do not
have the noexec stack option set.
NOTE: Some older versions of RedHat do not seem to be vulnerable
since they apparently do not allow anonymous
Exploit-DB
Samba 2.2.8 (OSX/PPC) - 'trans2open' Remote Overflow (Metasploit)
exploitdb·2010-06-21
CVE-2003-0201 Samba 2.2.8 (OSX/PPC) - 'trans2open' Remote Overflow (Metasploit)
Samba 2.2.8 (OSX/PPC) - 'trans2open' Remote Overflow (Metasploit)
---
##
# $Id: trans2open.rb 9571 2010-06-21 16:53:52Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Samba trans2open Overflow (Mac OS X PPC)',
'Description' => %q{
This exploits the buffer overflow found in Samba versions
2.2.0 to 2.2.8. This particular module is capable of
exploiting the bug on Mac OS X PowerPC systems.
},
'Author' => [ 'hdm', 'jduck' ],
'Version' => '$Revision: 9571 $',
'References' =>
[
[ 'CVE', '2003-0201' ],
[ 'OSVDB', '4469' ],
[ 'BID', '7294'
Exploit-DB
Samba 2.2.8 (Solaris SPARC) - 'trans2open' Remote Overflow (Metasploit)
exploitdb·2010-06-21
CVE-2003-0201 Samba 2.2.8 (Solaris SPARC) - 'trans2open' Remote Overflow (Metasploit)
Samba 2.2.8 (Solaris SPARC) - 'trans2open' Remote Overflow (Metasploit)
---
##
# $Id: trans2open.rb 9571 2010-06-21 16:53:52Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Samba trans2open Overflow (Solaris SPARC)',
'Description' => %q{
This exploits the buffer overflow found in Samba versions
2.2.0 to 2.2.8. This particular module is capable of
exploiting the flaw on Solaris SPARC systems that do not
have the noexec stack option set. Big thanks to MC and
valsmith for resolving a problem with the beta version of
this module.
},
'A
Exploit-DB
Samba 2.2.8 (BSD x86) - 'trans2open' Remote Overflow (Metasploit)
exploitdb·2010-06-17
CVE-2003-0201 Samba 2.2.8 (BSD x86) - 'trans2open' Remote Overflow (Metasploit)
Samba 2.2.8 (BSD x86) - 'trans2open' Remote Overflow (Metasploit)
---
##
# $Id: trans2open.rb 9552 2010-06-17 22:11:43Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Samba trans2open Overflow (*BSD x86)',
'Description' => %q{
This exploits the buffer overflow found in Samba versions
2.2.0 to 2.2.8. This particular module is capable of
exploiting the flaw on x86 Linux systems that do not
have the noexec stack option set.
},
'Author' => [ 'hdm', 'jduck' ],
'License' => MSF_LICENSE,
'Version' => '$Revision: 9552 $',
'References' =>
[
http://www.adobe.com/support/security/bulletins/apsb10-09.htmlhttp://www.securityfocus.com/bid/39329http://www.us-cert.gov/cas/techalerts/TA10-103C.htmlhttp://www.vupen.com/english/advisories/2010/0873https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7056http://www.adobe.com/support/security/bulletins/apsb10-09.htmlhttp://www.securityfocus.com/bid/39329http://www.us-cert.gov/cas/techalerts/TA10-103C.htmlhttp://www.vupen.com/english/advisories/2010/0873https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7056
2010-04-14
Published