CVE-2011-0598
published 2011-02-10CVE-2011-0598: Integer overflow in ACE.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote…
PriorityP351critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
9.84%
95.0th percentile
Integer overflow in ACE.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code via crafted ICC data, a different vulnerability than CVE-2011-0596, CVE-2011-0599, and CVE-2011-0602.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
acroread: critical APSB11-03
vendor_redhat·2011-02-08·CVSS 9.3
CVE-2011-0596 [CRITICAL] acroread: critical APSB11-03
acroread: critical APSB11-03
The Bitmap parsing component in 2d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via an image with crafted (1) height and (2) width values for an RLE_8 compressed bitmap, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2011-0598, CVE-2011-0599, and CVE-2011-0602.
Red Hat
acroread: critical APSB11-03
vendor_redhat·2011-02-08·CVSS 9.3
CVE-2011-0599 [CRITICAL] acroread: critical APSB11-03
acroread: critical APSB11-03
The Bitmap parsing component in rt3d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted image that causes an invalid pointer calculation related to 4/8-bit RLE compression, a different vulnerability than CVE-2011-0596, CVE-2011-0598, and CVE-2011-0602.
Red Hat
acroread: critical APSB11-03
vendor_redhat·2011-02-08·CVSS 9.3
CVE-2011-0602 [CRITICAL] acroread: critical APSB11-03
acroread: critical APSB11-03
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via crafted JP2K record types in a JPEG2000 image in a PDF file, which causes heap corruption, a different vulnerability than CVE-2011-0596, CVE-2011-0598, and CVE-2011-0599.
Red Hat
acroread: critical APSB11-03
vendor_redhat·2011-02-08·CVSS 9.3
CVE-2011-0598 [CRITICAL] acroread: critical APSB11-03
acroread: critical APSB11-03
Integer overflow in ACE.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code via crafted ICC data, a different vulnerability than CVE-2011-0596, CVE-2011-0599, and CVE-2011-0602.
GHSA
GHSA-525f-cx6r-p4wx: The Bitmap parsing component in 2d
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2011-0596 [CRITICAL] CWE-20 GHSA-525f-cx6r-p4wx: The Bitmap parsing component in 2d
The Bitmap parsing component in 2d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via an image with crafted (1) height and (2) width values for an RLE_8 compressed bitmap, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2011-0598, CVE-2011-0599, and CVE-2011-0602.
GHSA
GHSA-q4vg-98mm-69wh: The Bitmap parsing component in rt3d
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2011-0599 [CRITICAL] CWE-20 GHSA-q4vg-98mm-69wh: The Bitmap parsing component in rt3d
The Bitmap parsing component in rt3d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted image that causes an invalid pointer calculation related to 4/8-bit RLE compression, a different vulnerability than CVE-2011-0596, CVE-2011-0598, and CVE-2011-0602.
GHSA
GHSA-q8vr-3rj5-9h8v: Integer overflow in ACE
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2011-0598 [CRITICAL] GHSA-q8vr-3rj5-9h8v: Integer overflow in ACE
Integer overflow in ACE.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code via crafted ICC data, a different vulnerability than CVE-2011-0596, CVE-2011-0599, and CVE-2011-0602.
GHSA
GHSA-fjgw-mh3v-fgr9: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2011-0602 [CRITICAL] CWE-20 GHSA-fjgw-mh3v-fgr9: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via crafted JP2K record types in a JPEG2000 image in a PDF file, which causes heap corruption, a different vulnerability than CVE-2011-0596, CVE-2011-0598, and CVE-2011-0599.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/43470http://www.adobe.com/support/security/bulletins/apsb11-03.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0301.htmlhttp://www.securityfocus.com/archive/1/516315/100/0/threadedhttp://www.securityfocus.com/bid/46219http://www.securitytracker.com/id?1025033http://www.vupen.com/english/advisories/2011/0337http://www.vupen.com/english/advisories/2011/0492http://www.zerodayinitiative.com/advisories/ZDI-11-073/https://exchange.xforce.ibmcloud.com/vulnerabilities/65302https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12081http://secunia.com/advisories/43470http://www.adobe.com/support/security/bulletins/apsb11-03.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0301.htmlhttp://www.securityfocus.com/archive/1/516315/100/0/threadedhttp://www.securityfocus.com/bid/46219http://www.securitytracker.com/id?1025033http://www.vupen.com/english/advisories/2011/0337http://www.vupen.com/english/advisories/2011/0492http://www.zerodayinitiative.com/advisories/ZDI-11-073/https://exchange.xforce.ibmcloud.com/vulnerabilities/65302https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12081
2011-02-10
Published