CVE-2012-2025
published 2012-05-09CVE-2012-2025: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.38%
91.7th percentile
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator_cs5.5 | <= 15 | — |
| msrc | azl3_accountsservice_23.13.9-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_boost_1.83.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_cal10n_0.8.1.10-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_fontawesome4-fonts_4.7.0-12_on_azure_linux_3.0 | — | — |
| msrc | azl3_javapackages-bootstrap_1.14.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-blinker_1.7.0-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-tensorboard_2.16.2-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-14_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-38p9-j94m-w67p: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0780 [CRITICAL] CWE-119 GHSA-38p9-j94m-w67p: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
GHSA
GHSA-mqr5-ffq5-hrp4: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2024 [CRITICAL] CWE-119 GHSA-mqr5-ffq5-hrp4: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.
GHSA
GHSA-c895-43rw-5x9c: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2025 [CRITICAL] CWE-119 GHSA-c895-43rw-5x9c: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.
GHSA
GHSA-5c6j-76f2-jq69: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2023 [CRITICAL] CWE-119 GHSA-5c6j-76f2-jq69: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
GHSA
GHSA-3wqx-wh6r-cf85: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2026 [CRITICAL] CWE-119 GHSA-3wqx-wh6r-cf85: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.
GHSA
GHSA-cgw2-g5cm-vwm6: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2042 [CRITICAL] CWE-119 GHSA-cgw2-g5cm-vwm6: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
Red Hat
kernel: clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context
vendor_redhat·2025-02-27·CVSS 5.5
CVE-2025-21767 [MEDIUM] CWE-662 kernel: clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context
kernel: clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context
In the Linux kernel, the following vulnerability has been resolved:
clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context
The following bug report happened with a PREEMPT_RT kernel:
BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48
in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 2012, name: kwatchdog
preempt_count: 1, expected: 0
RCU nest depth: 0, expected: 0
get_random_u32+0x4f/0x110
clocksource_verify_choose_cpus+0xab/0x1a0
clocksource_verify_percpu.part.0+0x6b/0x330
clocksource_watchdog_kthread+0x193/0x1a0
It is due to the fact that clocksource_verify_choose_cpus() is invoked with
preemption disabled. This function i
Microsoft
MapUrlToZone Security Feature Bypass Vulnerability
vendor_msrc·2025-01-14·CVSS 4.3
CVE-2025-21332 [MEDIUM] CWE-41 MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
FAQ: The Security Updates table indicates that this vulnerability affects all supported versions of Microsoft Windows. Why are IE Cumulative updates listed for Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2?
While Microsoft has announced retirement of the Internet Explorer 11 application on certain platforms and the Microsoft Edge Legacy application is deprecated, the underlying MSHTML, EdgeHTML, and scripting platforms are still supported. The MSHTML platform is used by Internet Explorer mode in Microsoft Edge as well as other applications through WebBrowser control. The EdgeHTML platform is used by WebView and some UWP applications. The scripting platforms are used by MSHTML and EdgeHTML but
Microsoft
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
vendor_msrc·2019-11-12·CVSS 3.3
CVE-2012-6655 [LOW] An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
m
Microsoft
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions jQuery d
vendor_msrc·2018-01-09·CVSS 6.1
CVE-2012-6708 [MEDIUM] CWE-79 jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions jQuery d
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions jQuery determined whether the input was HTML by looking for the 'Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to add
Citrix
Citrix Security Bulletin CTX135066
vendor_citrix·CVSS 9.3
CVE-2012-5161 [CRITICAL] Citrix Security Bulletin CTX135066
Citrix Security Bulletin CTX135066
CVE References: CVE-2012-5161, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX133161
vendor_citrix·CVSS 7.2
CVE-2012-0217 [HIGH] Citrix Security Bulletin CTX133161
Citrix Security Bulletin CTX133161
CVE References: CVE-2012-0217, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX134708
vendor_citrix·CVSS 2.1
CVE-2012-3494 [LOW] Citrix Security Bulletin CTX134708
Citrix Security Bulletin CTX134708
CVE References: CVE-2012-3494, CVE-2012-3495, CVE-2012-3496, CVE-2012-3498, CVE-2012-3516, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX135813
vendor_citrix·CVSS 5.0
CVE-2012-6314 [MEDIUM] Citrix Security Bulletin CTX135813
Citrix Security Bulletin CTX135813
CVE References: CVE-2012-6314, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft patches Windows Kernel zero-day exploited since 2023
blogs_bleepingcomputer·2025-03-12·CVSS 7.8
CVE-2025-24983 [HIGH] Microsoft patches Windows Kernel zero-day exploited since 2023
## Microsoft patches Windows Kernel zero-day exploited since 2023
## Sergiu Gatlan
ESET said on Tuesday that a zero-day exploit targeting the CVE-2025-24983 vulnerability was "first seen in the wild" in March 2023 on systems backdoored using PipeMagic malware.
This exploit targets only older Windows versions (Windows Server 2012 R2 and Windows 8.1) that Microsoft no longer supports. However, the vulnerability also affects newer Windows versions, including the still-supported Windows Server 2016 and Windows 10 systems running Windows 10 build 1809 and earlier.
"The Use-After-Free (UAF) vulnerability is related to improper memory usage during software operation. This can lead to software crashes, execution of malicious code (including remotely), privilege escalation, or data corruption,"
Tenable
Nessus 5.0.2 Available
blogs_tenable·2012-10-10·CVSS 5.3
[MEDIUM] Nessus 5.0.2 Available
Blog /
Subscribe
# Nessus 5.0.2 Available
Ron Gula
October 10, 2012
0 Min Read
Nessus 5.0.2 has been released and is available at http://www.nessus.org/download/. This update is largely a bugfix release, however a new build for Solaris 10 is now available.
The major issues addressed in 5.0.2 include enhanced support for UTF8 encoding problems in reports and the detection of network congestion errors during scans more conservatively. For a full list of addressed issues, please review the 5.0.2 availability announcement at the Nessus Discussion Forums.
## Related articles
May 13, 2025
## CVE-2025-4427, CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Remote Code Execution
Remote code execution vulnerability in a popular mobile device management solution from Ivanti has been exp
http://osvdb.org/81757http://www.adobe.com/support/security/bulletins/apsb12-10.htmlhttp://www.securityfocus.com/bid/53422http://www.securitytracker.com/id?1027047https://exchange.xforce.ibmcloud.com/vulnerabilities/75448http://osvdb.org/81757http://www.adobe.com/support/security/bulletins/apsb12-10.htmlhttp://www.securityfocus.com/bid/53422http://www.securitytracker.com/id?1027047https://exchange.xforce.ibmcloud.com/vulnerabilities/75448
2012-05-09
Published