CVE-2010-3627
published 2010-10-06CVE-2010-3627: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code…
PriorityP349critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.98%
93.5th percentile
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via unknown vectors.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
acroread: multiple code execution flaws (APSB10-21)
vendor_redhat·2010-10-05·CVSS 9.3
CVE-2010-3627 [CRITICAL] acroread: multiple code execution flaws (APSB10-21)
acroread: multiple code execution flaws (APSB10-21)
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via unknown vectors.
Package: acroread (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-h9c2-3p3h-qc69: Unspecified vulnerability in Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-14
CVE-2010-3627 [HIGH] CWE-20 GHSA-h9c2-3p3h-qc69: Unspecified vulnerability in Adobe Reader and Acrobat 9
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3840 MySQL: crash when loading data into geometry function PolyFromWKB() (MySQL Bug#51875)
bugzilla·2010-10-07·CVSS 4.0
CVE-2010-3840 [MEDIUM] CVE-2010-3840 MySQL: crash when loading data into geometry function PolyFromWKB() (MySQL Bug#51875)
CVE-2010-3840 MySQL: crash when loading data into geometry function PolyFromWKB() (MySQL Bug#51875)
A flaw in MySQL versions prior to 5.1.51 [1] was reported [2] that could allow an authenticated user to cause the MySQL server to crash when improper WKB data was passed to the PolyFromWKB() function.
There is an upstream patch [3] to correct the issue.
[1] http://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.html
[2] http://bugs.mysql.com/bug.php?id=51875
[3] http://lists.mysql.com/commits/117094
Discussion:
This issue has been assigned the name CVE-2010-3840:
http://article.gmane.org/gmane.comp.security.oss.general/3627
---
Created attachment 453413
upstream patch
---
This issue did NOT affect the versions of the mysql package, as shipped with
Red Hat Enterprise Linux 3
This issue
Bugzilla
CVE-2010-3834 MySQL: user variable assignments crash server when used within query (MySQL Bug#55568)
bugzilla·2010-10-06·CVSS 4.0
CVE-2010-3834 [MEDIUM] CVE-2010-3834 MySQL: user variable assignments crash server when used within query (MySQL Bug#55568)
CVE-2010-3834 MySQL: user variable assignments crash server when used within query (MySQL Bug#55568)
A flaw in MySQL versions prior to 5.1.51 [1] was reported [2] that could allow an authenticated user to kill connections to MySQL, where the server could crash after materializing a derived table that required a temporary table for grouping.
[1] http://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.html
[2] http://bugs.mysql.com/bug.php?id=55568
Discussion:
This issue has been assigned the name CVE-2010-3834:
http://article.gmane.org/gmane.comp.security.oss.general/3627
---
Created attachment 453410
upstream patch
---
This issue did NOT affect the versions of mysql as shipped with Fedora 12 and Fedora 13.
---
Statement:
Not vulnerable. This issue did not affect the versions of mysq
Bugzilla
CVE-2010-3835 MySQL: crash with user variables, assignments, joins... (MySQL Bug #55564)
bugzilla·2010-10-06·CVSS 4.0
CVE-2010-3835 [MEDIUM] CVE-2010-3835 MySQL: crash with user variables, assignments, joins... (MySQL Bug #55564)
CVE-2010-3835 MySQL: crash with user variables, assignments, joins... (MySQL Bug #55564)
A flaw in MySQL versions prior to 5.1.51 [1] was reported [2] that could allow
an authenticated user to kill connections to MySQL. A user-variable assignment expression that is evaluated in a logical expression context can be precalculated in a temporary table for GROUP BY. However, when the expression value is used after creation of the temporary table, it was re-evaluated, not read from the table and a server crash resulted.
[1] http://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.html
[2] http://bugs.mysql.com/bug.php?id=55564
Discussion:
This issue has been assigned the name CVE-2010-3835:
http://article.gmane.org/gmane.comp.security.oss.general/3627
---
Created attachment 453408
upstream patc
Bugzilla
CVE-2010-3833 MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)
bugzilla·2010-10-06·CVSS 5.0
CVE-2010-3833 [MEDIUM] CVE-2010-3833 MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)
CVE-2010-3833 MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)
A flaw in MySQL versions prior to 5.1.51 [1] was reported [2] that could allow an authenticated user to kill connections to MySQL. During evaluation of arguments to extreme-value functions (such as LEAST() and GREATEST()), type errors did not propagate properly, causing the server to crash, and any other connections to the server to be terminated.
[1] http://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.html
[2] http://bugs.mysql.com/bug.php?id=55826
Discussion:
This issue has been assigned the name CVE-2010-3833:
http://article.gmane.org/gmane.comp.security.oss.general/3627
---
Created attachment 453399
upstream patch
---
This issue did NOT affect the versions of the mysql pac
Bugzilla
CVE-2010-3838 MySQL: crash with LONGBLOB and union or update with subquery (MySQL Bug#54461)
bugzilla·2010-10-06·CVSS 4.0
CVE-2010-3838 [MEDIUM] CVE-2010-3838 MySQL: crash with LONGBLOB and union or update with subquery (MySQL Bug#54461)
CVE-2010-3838 MySQL: crash with LONGBLOB and union or update with subquery (MySQL Bug#54461)
A flaw in MySQL versions prior to 5.1.51 [1] was reported [2] that could allow an authenticated user to kill connections to MySQL by creating a query with the GREATEST() or LEAST() functions having a mixed list of numeric and LONGBLOB arguments.
[1] http://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.html
[2] http://bugs.mysql.com/bug.php?id=54461
This is noted as having been fixed in MySQL 5.1.51, but it does not cause a crash on MySQL 5.0.50 in Fedora 13. It also causes a crash on Red Hat Enterprise Linux 5 (5.0.77) but not Red Hat Enterprise Linux 4 (4.1.22).
Discussion:
This issue has been assigned the name CVE-2010-3838:
http://article.gmane.org/gmane.comp.security.oss.general/3627
---
Bugzilla
acroread: multiple code execution flaws (APSB10-21)
bugzilla·2010-10-04·CVSS 7.3
CVE-2010-2883 [HIGH] acroread: multiple code execution flaws (APSB10-21)
acroread: multiple code execution flaws (APSB10-21)
Adobe security bulletin APSB10-21 describes multiple security flaws that can lead to arbitrary code execution when malicious PDF file is opened in Adobe Reader.
http://www.adobe.com/support/security/bulletins/apsb10-21.html
Two of the issues were previously public, as they were exploited in the wild:
This update resolves a font-parsing input validation vulnerability that could lead to code execution (CVE-2010-2883). (see bug #632267)
This update resolves a memory corruption vulnerability in the authplay.dll component that could lead to code execution (CVE-2010-2884). (see bug #633917, affects embedded Flash player)
Additional issues with possible code execution impact:
This update resolves a font-parsing input validation vulnerabil
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.htmlhttp://secunia.com/advisories/43025http://security.gentoo.org/glsa/glsa-201101-08.xmlhttp://www.adobe.com/support/security/bulletins/apsb10-21.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0743.htmlhttp://www.us-cert.gov/cas/techalerts/TA10-279A.htmlhttp://www.vupen.com/english/advisories/2011/0191https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7356http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.htmlhttp://secunia.com/advisories/43025http://security.gentoo.org/glsa/glsa-201101-08.xmlhttp://www.adobe.com/support/security/bulletins/apsb10-21.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0743.htmlhttp://www.us-cert.gov/cas/techalerts/TA10-279A.htmlhttp://www.vupen.com/english/advisories/2011/0191https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7356
2010-10-06
Published