CVE-2011-2101
published 2011-06-16CVE-2011-2101: Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X do not properly restrict script, which allows attackers…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.97%
93.4th percentile
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X do not properly restrict script, which allows attackers to execute arbitrary code via a crafted document, related to a "cross document script execution vulnerability."
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rq58-343g-rcp4: Adobe Reader and Acrobat 8
ghsa_unreviewed·2022-05-17
CVE-2011-2101 [HIGH] CWE-94 GHSA-rq58-343g-rcp4: Adobe Reader and Acrobat 8
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X do not properly restrict script, which allows attackers to execute arbitrary code via a crafted document, related to a "cross document script execution vulnerability."
GHSA
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
ghsa·2022-05-17
CVE-2012-2101 [LOW] Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
Red Hat
acroread: multiple code execution flaws (APSB11-16)
vendor_redhat·2011-06-14·CVSS 9.3
CVE-2011-2101 [CRITICAL] acroread: multiple code execution flaws (APSB11-16)
acroread: multiple code execution flaws (APSB11-16)
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X do not properly restrict script, which allows attackers to execute arbitrary code via a crafted document, related to a "cross document script execution vulnerability."
No detection rules found.
No public exploits indexed.
http://osvdb.org/73063http://www.adobe.com/support/security/bulletins/apsb11-16.htmlhttp://www.securityfocus.com/bid/48255http://www.securitytracker.com/id?1025658http://www.us-cert.gov/cas/techalerts/TA11-166A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/68015https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13919http://osvdb.org/73063http://www.adobe.com/support/security/bulletins/apsb11-16.htmlhttp://www.securityfocus.com/bid/48255http://www.securitytracker.com/id?1025658http://www.us-cert.gov/cas/techalerts/TA11-166A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/68015https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13919
2011-06-16
Published