CVE-2015-3072
published 2015-05-13CVE-2015-3072: Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API…
PriorityP346critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.92%
95.1th percentile
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3073, and CVE-2015-3074.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cf9h-6v77-3345: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3061 [CRITICAL] CWE-284 GHSA-cf9h-6v77-3345: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-fpq5-qvqr-5pw9: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3066 [CRITICAL] CWE-284 GHSA-fpq5-qvqr-5pw9: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-37x6-phq8-3rmq: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3062 [CRITICAL] CWE-284 GHSA-37x6-phq8-3rmq: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-6fp3-r4pr-85gr: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3072 [CRITICAL] CWE-284 GHSA-6fp3-r4pr-85gr: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-p77r-p748-87qx: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3064 [CRITICAL] CWE-284 GHSA-p77r-p748-87qx: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-28f5-mg2c-r34c: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3073 [CRITICAL] CWE-284 GHSA-28f5-mg2c-r34c: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.
GHSA
GHSA-mm83-hc7p-5mw5: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3069 [CRITICAL] CWE-284 GHSA-mm83-hc7p-5mw5: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-2wm5-c3g6-vrfw: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3068 [CRITICAL] CWE-284 GHSA-2wm5-c3g6-vrfw: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-64q2-rq62-qq2m: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3060 [CRITICAL] CWE-284 GHSA-64q2-rq62-qq2m: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-gmr5-mjx8-3c9q: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3063 [CRITICAL] CWE-284 GHSA-gmr5-mjx8-3c9q: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-gq5v-9p2w-97m2: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3067 [CRITICAL] CWE-284 GHSA-gq5v-9p2w-97m2: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-62jc-v45x-88m6: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3065 [CRITICAL] CWE-284 GHSA-62jc-v45x-88m6: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
GHSA
GHSA-3cq9-9wpc-c893: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3074 [CRITICAL] CWE-284 GHSA-3cq9-9wpc-c893: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3073.
GHSA
GHSA-j43x-5546-gfgm: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3071 [CRITICAL] CWE-284 GHSA-j43x-5546-gfgm: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.
Red Hat
kernel: udmabuf: change folios array from kmalloc to kvmalloc
vendor_redhat·2024-12-27·CVSS 5.5
CVE-2024-56544 [MEDIUM] CWE-476 kernel: udmabuf: change folios array from kmalloc to kvmalloc
kernel: udmabuf: change folios array from kmalloc to kvmalloc
In the Linux kernel, the following vulnerability has been resolved:
udmabuf: change folios array from kmalloc to kvmalloc
When PAGE_SIZE 4096, MAX_PAGE_ORDER 10, 64bit machine,
page_alloc only support 4MB.
If above this, trigger this warn and return NULL.
udmabuf can change size limit, if change it to 3072(3GB), and then alloc
3GB udmabuf, will fail create.
[ 4080.876581] ------------[ cut here ]------------
[ 4080.876843] WARNING: CPU: 3 PID: 2015 at mm/page_alloc.c:4556 __alloc_pages+0x2c8/0x350
[ 4080.878839] RIP: 0010:__alloc_pages+0x2c8/0x350
[ 4080.879470] Call Trace:
[ 4080.879473]
[ 4080.879473] ? __alloc_pages+0x2c8/0x350
[ 4080.879475] ? __warn.cold+0x8e/0xe8
[ 4080.880647] ? __alloc_pages+0x2c8/0x350
[ 4080.880909] ?
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/74604http://www.securitytracker.com/id/1032284http://www.zerodayinitiative.com/advisories/ZDI-15-196https://helpx.adobe.com/security/products/reader/apsb15-10.htmlhttp://www.securityfocus.com/bid/74604http://www.securitytracker.com/id/1032284http://www.zerodayinitiative.com/advisories/ZDI-15-196https://helpx.adobe.com/security/products/reader/apsb15-10.html
2015-05-13
Published