CVE-2011-4372Out-of-bounds Write in Adobe Acrobat

CWE-787Out-of-bounds Write13 documents5 sources
Severity
9.8CRITICALNVD
NVD7.5CNA7.5
EPSS
7.0%
top 8.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 10
Latest updateMay 13

Description

Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4373.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDadobe/reader10.1.1+4
NVDadobe/acrobat10.1.1+4

Patches

🔴Vulnerability Details

6
GHSA
GHSA-j8vc-rf9f-c27g: Adobe Reader and Acrobat before 92022-05-13
GHSA
GHSA-7cc2-5wx7-mm67: Adobe Reader and Acrobat before 92022-05-13
GHSA
GHSA-xv37-xpc4-25wq: Adobe Reader and Acrobat before 92022-05-13
CVEList
CVE-2011-4373: Adobe Reader and Acrobat before 92012-01-10
CVEList
CVE-2011-4372: Adobe Reader and Acrobat before 92012-01-10

📋Vendor Advisories

3
Red Hat
acroread: multiple unspecified flaws (APSB12-08, APSB12-01)2012-04-05
Red Hat
acroread: multiple unspecified flaws (APSB12-08, APSB12-01)2012-04-05
Red Hat
acroread: multiple unspecified flaws (APSB12-08, APSB12-01)2012-04-05

💬Community

1
Bugzilla
CVE-2011-4370 CVE-2011-4371 CVE-2011-4372 CVE-2011-4373 CVE-2012-0774 CVE-2012-0775 CVE-2012-0777 acroread: multiple unspecified flaws (APSB12-08, APSB12-01)2012-04-05
CVE-2011-4372 — Out-of-bounds Write in Adobe Acrobat | cvebase