CVE-2012-2051
published 2012-08-15CVE-2012-2051: Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service…
PriorityP348critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.53%
93.9th percentile
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xmp2-p923-f7r4: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4152 [CRITICAL] CWE-119 GHSA-xmp2-p923-f7r4: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-jpqf-j65q-4fxr: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4150 [CRITICAL] CWE-119 GHSA-jpqf-j65q-4fxr: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-5jjp-w7h3-pf23: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4158 [CRITICAL] CWE-119 GHSA-5jjp-w7h3-pf23: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-9vf6-prxr-gqg8: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4147 [CRITICAL] CWE-119 GHSA-9vf6-prxr-gqg8: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-cv9p-5v5f-g9j2: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4151 [CRITICAL] CWE-119 GHSA-cv9p-5v5f-g9j2: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-7mjq-vm25-3c8g: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4154 [CRITICAL] CWE-119 GHSA-7mjq-vm25-3c8g: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-26gj-f778-xvm7: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4153 [CRITICAL] CWE-119 GHSA-26gj-f778-xvm7: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-2cg3-25v4-3fx8: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2051 [CRITICAL] CWE-119 GHSA-2cg3-25v4-3fx8: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-f8cr-fm37-g5fw: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4149 [CRITICAL] CWE-119 GHSA-f8cr-fm37-g5fw: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-qmv8-7c72-w47h: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4155 [CRITICAL] CWE-119 GHSA-qmv8-7c72-w47h: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-gr9r-wcvc-m84r: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4160 [CRITICAL] CWE-119 GHSA-gr9r-wcvc-m84r: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, and CVE-2012-4159.
GHSA
GHSA-64mj-c3pq-q2qj: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4159 [CRITICAL] CWE-119 GHSA-64mj-c3pq-q2qj: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, and CVE-2012-4160.
GHSA
GHSA-9gpj-fp4c-cqjp: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4157 [CRITICAL] CWE-119 GHSA-9gpj-fp4c-cqjp: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-8ggf-qhcg-9vjr: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4148 [CRITICAL] CWE-119 GHSA-8ggf-qhcg-9vjr: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
GHSA
GHSA-68wc-gmpx-3rgg: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-4156 [CRITICAL] CWE-119 GHSA-68wc-gmpx-3rgg: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Red Hat
tomcat: DIGEST authentication vulnerable to replay attacks
vendor_redhat·2013-05-28·CVSS 5.0
CVE-2013-2051 [MEDIUM] tomcat: DIGEST authentication vulnerable to replay attacks
tomcat: DIGEST authentication vulnerable to replay attacks
The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale. NOTE: this issue is due to an incomplete fix for CVE-2012-5887.
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4155 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4149 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4159 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4157 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4147 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-2051 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4151 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4156 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4150 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4152 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4154 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4160 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, and CVE-2012-4159.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4153 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4158 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
Red Hat
acroread: multiple code execution flaw (APSB12-16)
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-4148 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.
Package: acroread (Red Hat Enterprise Linux 5) - Affected
Package: acroread (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
bugzilla·2013-05-03·CVSS 5.0
CVE-2013-2051 [MEDIUM] CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
It was found that the fix for CVE-2012-5887 shipped for tomcat 6 on Red Hat Enterprise Linux 6 (RHSA-2013:0623) was incomplete. The fix only allowed DIGEST authentication to succeed when a stale nonce was provided, rather than when a stale nonce was NOT provided. As a result, DIGEST authentication did not function. However, a man-in-the-middle attacker could record a DIGEST authentication exchange, wait until the associated nonce is marked as stale on the server, then successfully replay this request.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0869 https://rhn.redhat.com/errata/RHSA-2013-0869.html
Bugzilla
acroread: multiple code execution flaw (APSB12-16)
bugzilla·2012-08-14·CVSS 10.0
CVE-2012-2049 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe security bulletin APSB12-16 describes numerous security flaws that can lead to arbitrary code exection in Adobe Reader:
These updates resolve a stack overflow vulnerability that could lead to code execution (CVE-2012-2049).
These updates resolve a buffer overflow vulnerability that could lead to code execution (CVE-2012-2050).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, CVE-2012-4160).
These updates resolve a heap overflow vulnerability that could lead to code execution (CVE-2
http://security.gentoo.org/glsa/glsa-201308-03.xmlhttp://www.adobe.com/support/security/bulletins/apsb12-16.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16394http://security.gentoo.org/glsa/glsa-201308-03.xmlhttp://www.adobe.com/support/security/bulletins/apsb12-16.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16394
2012-08-15
Published