CVE-2011-2437
published 2011-09-15CVE-2011-2437: Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.94%
92.4th percentile
Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2433 and CVE-2011-2434.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6qgf-mr2h-7xq2: Heap-based buffer overflow in Adobe Reader and Acrobat 8
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2011-2433 [CRITICAL] CWE-119 GHSA-6qgf-mr2h-7xq2: Heap-based buffer overflow in Adobe Reader and Acrobat 8
Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2434 and CVE-2011-2437.
GHSA
GHSA-m7jf-gqwv-h989: Heap-based buffer overflow in Adobe Reader and Acrobat 8
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2011-2437 [CRITICAL] CWE-119 GHSA-m7jf-gqwv-h989: Heap-based buffer overflow in Adobe Reader and Acrobat 8
Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2433 and CVE-2011-2434.
GHSA
GHSA-8qvr-rppr-cp78: Heap-based buffer overflow in Adobe Reader and Acrobat 8
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2011-2434 [CRITICAL] CWE-119 GHSA-8qvr-rppr-cp78: Heap-based buffer overflow in Adobe Reader and Acrobat 8
Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2433 and CVE-2011-2437.
Red Hat
acroread: multiple code execution flaws (APSB11-24)
vendor_redhat·2011-09-13·CVSS 9.3
CVE-2011-2433 [CRITICAL] acroread: multiple code execution flaws (APSB11-24)
acroread: multiple code execution flaws (APSB11-24)
Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2434 and CVE-2011-2437.
Red Hat
acroread: multiple code execution flaws (APSB11-24)
vendor_redhat·2011-09-13·CVSS 9.3
CVE-2011-2437 [CRITICAL] acroread: multiple code execution flaws (APSB11-24)
acroread: multiple code execution flaws (APSB11-24)
Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2433 and CVE-2011-2434.
Red Hat
acroread: multiple code execution flaws (APSB11-24)
vendor_redhat·2011-09-13·CVSS 9.3
CVE-2011-2434 [CRITICAL] acroread: multiple code execution flaws (APSB11-24)
acroread: multiple code execution flaws (APSB11-24)
Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2433 and CVE-2011-2437.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00025.htmlhttp://www.adobe.com/support/security/bulletins/apsb11-24.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13984http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00025.htmlhttp://www.adobe.com/support/security/bulletins/apsb11-24.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13984
2011-09-15
Published