CVE-2012-4161
published 2012-08-15CVE-2012-4161: Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory…
PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.64%
88.4th percentile
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4162.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jhwv-crf7-9fvg: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2012-4161 [HIGH] CWE-119 GHSA-jhwv-crf7-9fvg: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4162.
GHSA
GHSA-vmfg-v47m-gpjc: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2012-4162 [HIGH] CWE-119 GHSA-vmfg-v47m-gpjc: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4161.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4161 gksu-polkit: improper patching of CVE-2012-5617
bugzilla·2013-07-23·CVSS 7.8
CVE-2013-4161 [HIGH] CVE-2013-4161 gksu-polkit: improper patching of CVE-2012-5617
CVE-2013-4161 gksu-polkit: improper patching of CVE-2012-5617
It was found that the patch to correct CVE-2012-5617 (bug #883162) was improperly applied, so the vulnerability described by CVE-2012-5617 was never really fixed.
As a result, gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue, however it did not. Similarly, the version in Fedora 19 is still vulnerable to this flaw.
Discussion:
Created gksu-polkit tracking bugs for this issue:
Affects: fedora-all [bug 987562]
---
gksu-polkit-0.0.3-8.gitf8ce834c.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
---
gksu-polkit-0.0.3-8.gitf8ce834c.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in
Bugzilla
acroread: multiple code execution flaw (APSB12-16)
bugzilla·2012-08-14·CVSS 10.0
CVE-2012-2049 [CRITICAL] acroread: multiple code execution flaw (APSB12-16)
acroread: multiple code execution flaw (APSB12-16)
Adobe security bulletin APSB12-16 describes numerous security flaws that can lead to arbitrary code exection in Adobe Reader:
These updates resolve a stack overflow vulnerability that could lead to code execution (CVE-2012-2049).
These updates resolve a buffer overflow vulnerability that could lead to code execution (CVE-2012-2050).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, CVE-2012-4160).
These updates resolve a heap overflow vulnerability that could lead to code execution (CVE-2
2012-08-15
Published