CVE-2012-2026
published 2012-05-09CVE-2012-2026: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.38%
91.7th percentile
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator_cs5.5 | <= 15 | — |
| apache | guacamole | — | — |
| apache | httpd | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_23h2 | — | — |
| msrc | windows_11_version_24h2 | — | — |
| msrc | windows_11_version_25h2 | — | — |
| msrc | windows_11_version_26h1 | — | — |
| msrc | windows_server_2012 | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
ghsa4.9MEDIUM
cisa7.8HIGH
vendor_apache7.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
ghsa·2026-05-28·CVSS 4.9
CVE-2026-44394 [MEDIUM] CWE-863 OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity
GHSA
GHSA-38p9-j94m-w67p: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0780 [CRITICAL] CWE-119 GHSA-38p9-j94m-w67p: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
GHSA
GHSA-mqr5-ffq5-hrp4: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2024 [CRITICAL] CWE-119 GHSA-mqr5-ffq5-hrp4: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.
GHSA
GHSA-c895-43rw-5x9c: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2025 [CRITICAL] CWE-119 GHSA-c895-43rw-5x9c: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.
GHSA
GHSA-5c6j-76f2-jq69: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2023 [CRITICAL] CWE-119 GHSA-5c6j-76f2-jq69: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
GHSA
GHSA-3wqx-wh6r-cf85: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2026 [CRITICAL] CWE-119 GHSA-3wqx-wh6r-cf85: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.
GHSA
GHSA-cgw2-g5cm-vwm6: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2042 [CRITICAL] CWE-119 GHSA-cgw2-g5cm-vwm6: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
CISA
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
cisa·2026-04-13·CVSS 7.8
CVE-2012-1854 [HIGH] CWE-426 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
Vulnerability: Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
Affected: Microsoft Visual Basic for Applications (VBA)
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-046 ; https://nvd.nist.gov/vuln/detail/CVE-2012-1854
Remediation Due Date: 2026-04-27
Microsoft
MapUrlToZone Security Feature Bypass Vulnerability
vendor_msrc·2026-03-10·CVSS 7.5
CVE-2026-23674 [HIGH] CWE-41 MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
Description: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited the vulnerability could bypass the MapURLToZone method.
FAQ: The Security Updates table indicates that this vulnerability affects all supported versions of Microsoft Windows. Why are IE Cumulative updates listed for Windows Server 2012, and Windows Server 2012 R2?
While Microsoft has announced retirement of the Internet Explorer 11 application on certain platforms and the Microsoft Edge Legacy application is deprecated, the underlying MSHTML, EdgeHT
Citrix
Citrix Security Bulletin CTX135066
vendor_citrix·CVSS 9.3
CVE-2012-5161 [CRITICAL] Citrix Security Bulletin CTX135066
Citrix Security Bulletin CTX135066
CVE References: CVE-2012-5161, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX133161
vendor_citrix·CVSS 7.2
CVE-2012-0217 [HIGH] Citrix Security Bulletin CTX133161
Citrix Security Bulletin CTX133161
CVE References: CVE-2012-0217, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Apache
Apache guacamole: CVE-2012-4415
vendor_apache·CVSS 7.5
CVE-2012-4415 [HIGH] Apache guacamole: CVE-2012-4415
Apache guacamole: CVE-2012-4415
A stack-based buffer overflow vulnerability was discovered in the guac_client_plugin_open() function in libguac in Guacamole before 0.6.3 which could allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name. Acknowledgements: We would like to thank Timo Juhani Lindfors for reporting this issue. Copyright © 2026 The Apache Software Foundation , Licensed under the Apache License, Version 2.0 . Apache Guacamole, Guacamole, Apache, the Apache oak leaf logo, and the Apache Guacamole project logo are trademarks or registered trademarks of The Apache Software Foundation.
Affected versions: 0.6.3
Citrix
Citrix Security Bulletin CTX134708
vendor_citrix·CVSS 2.1
CVE-2012-3494 [LOW] Citrix Security Bulletin CTX134708
Citrix Security Bulletin CTX134708
CVE References: CVE-2012-3494, CVE-2012-3495, CVE-2012-3496, CVE-2012-3498, CVE-2012-3516, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX135813
vendor_citrix·CVSS 5.0
CVE-2012-6314 [MEDIUM] Citrix Security Bulletin CTX135813
Citrix Security Bulletin CTX135813
CVE References: CVE-2012-6314, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Apache
Apache httpd: CVE-2012-0883
vendor_apache·CVSS 6.9
CVE-2012-0883 [LOW] Apache httpd: CVE-2012-0883
Apache httpd: CVE-2012-0883
Insecure handling of LD_LIBRARY_PATH was found that could lead to the current working directory to be searched for DSOs. This could allow a local user to execute code as root if an administrator runs apachectl from an untrusted directory. Reported to security team 2012-02-14 Issue public 2012-03-02 Update 2.4.2 released 2012-04-17 Update 2.2.23 released 2012-09-13 Affects 2.4.1, 2.2.22, 2.2.21, 2.2.20, 2.2.19, 2.2.18, 2.2.17, 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0 Copyright © 1997-2026 The Apache Software Foundation. Apache HTTP Server, Apache, the Apache logo and the Apache HTTP Server logo are either registered trademarks or trademarks of The Apache Software Foundation in the United States
Citrix
Citrix Security Bulletin CTX135777
vendor_citrix·CVSS 3.2
CVE-2012-5512 [LOW] Citrix Security Bulletin CTX135777
Citrix Security Bulletin CTX135777
CVE References: CVE-2012-5512, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX136163
vendor_citrix·CVSS 1.5
CVE-2012-5616 [LOW] Citrix Security Bulletin CTX136163
Citrix Security Bulletin CTX136163
CVE References: CVE-2012-5616, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
Bugzilla
CVE-2026-44394 openstack-keystone: OpenStack Keystone: Federated token rescoping allows indefinite access
bugzilla·2026-05-28·CVSS 4.9
CVE-2026-44394 [MEDIUM] CVE-2026-44394 openstack-keystone: OpenStack Keystone: Federated token rescoping allows indefinite access
CVE-2026-44394 openstack-keystone: OpenStack Keystone: Federated token rescoping allows indefinite access
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect
Bugzilla
CVE-2026-43409 kernel: kprobes: avoid crash when rmmod/insmod after ftrace killed
bugzilla·2026-05-08
CVE-2026-43409 [MEDIUM] CVE-2026-43409 kernel: kprobes: avoid crash when rmmod/insmod after ftrace killed
CVE-2026-43409 kernel: kprobes: avoid crash when rmmod/insmod after ftrace killed
In the Linux kernel, the following vulnerability has been resolved:
kprobes: avoid crash when rmmod/insmod after ftrace killed
After we hit ftrace is killed by some errors, the kernel crash if
we remove modules in which kprobe probes.
BUG: unable to handle page fault for address: fffffbfff805000d
PGD 817fcc067 P4D 817fcc067 PUD 817fc8067 PMD 101555067 PTE 0
Oops: Oops: 0000 [#1] SMP KASAN PTI
CPU: 4 UID: 0 PID: 2012 Comm: rmmod Tainted: G W OE
Tainted: [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE
RIP: 0010:kprobes_module_callback+0x89/0x790
RSP: 0018:ffff88812e157d30 EFLAGS: 00010a02
RAX: 1ffffffff805000d RBX: dffffc0000000000 RCX: ffffffff86a8de90
RDX: ffffed1025c2af9b RSI: 0000000000000008 RDI: fffffff
http://www.adobe.com/support/security/bulletins/apsb12-10.htmlhttp://www.securityfocus.com/bid/53422http://www.securitytracker.com/id?1027047https://exchange.xforce.ibmcloud.com/vulnerabilities/75449http://www.adobe.com/support/security/bulletins/apsb12-10.htmlhttp://www.securityfocus.com/bid/53422http://www.securitytracker.com/id?1027047https://exchange.xforce.ibmcloud.com/vulnerabilities/75449
2012-05-09
Published