CVE-2012-1530
published 2013-01-10CVE-2012-1530: Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.57%
94.5th percentile
Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing an XSL file that triggers memory corruption when the lang function processes XML data with a crafted node-set.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-897j-c2px-h972: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2013-0601 [CRITICAL] CWE-119 GHSA-897j-c2px-h972: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
GHSA
GHSA-532h-q782-w73v: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2013-0605 [CRITICAL] CWE-119 GHSA-532h-q782-w73v: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
GHSA
GHSA-j52q-7rp8-wgfj: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2013-0616 [CRITICAL] GHSA-j52q-7rp8-wgfj: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
GHSA
GHSA-qr3r-9qvv-xj4c: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2013-0620 [CRITICAL] CWE-119 GHSA-qr3r-9qvv-xj4c: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, and CVE-2013-0623.
GHSA
GHSA-gj65-qwj7-4qg8: Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17
CVE-2012-1530 [HIGH] CWE-119 GHSA-gj65-qwj7-4qg8: Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9
Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing an XSL file that triggers memory corruption when the lang function processes XML data with a crafted node-set.
GHSA
GHSA-5jf9-q6c3-84hf: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2013-0623 [CRITICAL] GHSA-5jf9-q6c3-84hf: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, and CVE-2013-0620.
GHSA
GHSA-j4xc-xfc9-rvqr: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2013-0619 [CRITICAL] CWE-119 GHSA-j4xc-xfc9-rvqr: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0620, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2012-1530 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing an XSL file that triggers memory corruption when the lang function processes XML data with a crafted node-set.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0623 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, and CVE-2013-0620.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0619 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0620, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0601 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0605 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0616 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0620 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, and CVE-2013-0623.
Red Hat
kernel: keys: NULL pointer deref in the user-defined key type
vendor_redhat·2011-11-15·CVSS 2.1
CVE-2011-4110 [LOW] CWE-476 kernel: keys: NULL pointer deref in the user-defined key type
kernel: keys: NULL pointer deref in the user-defined key type
The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4,
5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1479.html, https://rhn.redhat.com/errata/RHSA-2011-1530.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://ac
Red Hat
kernel: ext4: ext4_ext_insert_extent() kernel oops
vendor_redhat·2011-09-28·CVSS 4.0
CVE-2011-3638 [MEDIUM] kernel: ext4: ext4_ext_insert_extent() kernel oops
kernel: ext4: ext4_ext_insert_extent() kernel oops
fs/ext4/extents.c in the Linux kernel before 3.0 does not mark a modified extent as dirty in certain cases of extent splitting, which allows local users to cause a denial of service (system crash) via vectors involving ext4 umount and mount operations.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for EXT4 filesystem. It did not affect the Linux kernel as shipped with Red Hat Enterprise MRG as it has backported the upstream commit 667eff35 that addressed this issue. This has been addressed in Red Hat Enterprise Linux 5 and 6 via https://rhn.redhat.com/errata/RHSA-2012-0107.html and https://rhn.redhat.com/errata/RHSA-2011-1530.html.
Package: kern
Red Hat
kernel: no access restrictions of /proc/pid/* after setuid program exec
vendor_redhat·2011-02-07·CVSS 4.6
CVE-2011-1020 [MEDIUM] kernel: no access restrictions of /proc/pid/* after setuid program exec
kernel: no access restrictions of /proc/pid/* after setuid program exec
The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.
Statement: Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for this issue is not currently planned to be included in the future updates.
This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via RHSA-2012:0007, RHSA-2011:1530 and RHSA-2011:1253 respectively
No detection rules found.
No public exploits indexed.
Bugzilla
acroread: multiple code execution flaws (APSB13-02)
bugzilla·2013-01-09·CVSS 10.0
CVE-2012-1530 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe security bulletin APSB13-02 describes multiple security flaws that could cause Adobe Acrobat Reader to crash and potentially allow an attacker to take control of the affected system:
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, CVE-2013-0623).
These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2013-0602).
These updates resolve heap overflow vulnerabilities that could lead to code execution (CVE-2013-0603, CVE-2013-0604).
These updates resolve stack overflow vulnerabilities that could lead to code execution (CVE-2013-0610, CVE-2013-0626).
These updates r
Bugzilla
CVE-2011-4110 kernel: keys: NULL pointer deref in the user-defined key type
bugzilla·2011-11-04·CVSS 2.1
CVE-2011-4110 [LOW] CVE-2011-4110 kernel: keys: NULL pointer deref in the user-defined key type
CVE-2011-4110 kernel: keys: NULL pointer deref in the user-defined key type
A flaw was found in the way Linux kernel handled user-defined key types. An unprivileged local user could use this flaw to crash the system.
Reference:
https://lkml.org/lkml/2011/11/15/363
Discussion:
Created attachment 531725
CVE-2011-4110 proposed patch
---
Statement:
This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4,
5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1479.html, https://rhn.redhat.com/errata/RHSA-2011-1530.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https:
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00081.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0150.htmlhttp://security.gentoo.org/glsa/glsa-201308-03.xmlhttp://www.adobe.com/support/security/bulletins/apsb13-02.htmlhttp://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1019https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16094http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00081.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0150.htmlhttp://security.gentoo.org/glsa/glsa-201308-03.xmlhttp://www.adobe.com/support/security/bulletins/apsb13-02.htmlhttp://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1019https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16094
2013-01-10
Published