CVE-2015-3095
published 2015-07-15CVE-2015-3095: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat…
PriorityP348critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.82%
92.4th percentile
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5087, CVE-2015-5094, CVE-2015-5100, CVE-2015-5102, CVE-2015-5103, CVE-2015-5104, and CVE-2015-5115.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | >= 10.0 < 10.1.15 | 10.1.15 |
| adobe | acrobat | 10.0 – 10.1.14 | — |
| adobe | acrobat | >= 11.0.0 < 11.0.12 | 11.0.12 |
| adobe | acrobat | 11.0.0 – 11.0.11 | — |
| adobe | acrobat_dc | >= 15.006.30033 < 15.006.30060 | 15.006.30060 |
| adobe | acrobat_dc | >= 15.007.20033 < 15.008.20082 | 15.008.20082 |
| adobe | acrobat_reader | >= 10.0 < 10.1.15 | 10.1.15 |
| adobe | acrobat_reader | 10.0 – 10.1.14 | — |
| adobe | acrobat_reader | >= 11.0.0 < 11.0.12 | 11.0.12 |
| adobe | acrobat_reader | 11.0.0 – 11.0.11 | — |
| adobe | acrobat_reader_dc | >= 15.006.30033 < 15.006.30060 | 15.006.30060 |
| adobe | acrobat_reader_dc | >= 15.007.20033 < 15.008.20082 | 15.008.20082 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4gpm-6hmq-c6mr: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-5094 [CRITICAL] CWE-119 GHSA-4gpm-6hmq-c6mr: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3095, CVE-2015-5087, CVE-2015-5100, CVE-2015-5102, CVE-2015-5103, CVE-2015-5104, and CVE-2015-5115.
GHSA
GHSA-76fh-cw5x-fw6m: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-5103 [CRITICAL] CWE-119 GHSA-76fh-cw5x-fw6m: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3095, CVE-2015-5087, CVE-2015-5094, CVE-2015-5100, CVE-2015-5102, CVE-2015-5104, and CVE-2015-5115.
GHSA
GHSA-6xf7-p3jx-g67x: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-5115 [CRITICAL] CWE-119 GHSA-6xf7-p3jx-g67x: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3095, CVE-2015-5087, CVE-2015-5094, CVE-2015-5100, CVE-2015-5102, CVE-2015-5103, and CVE-2015-5104.
GHSA
GHSA-859j-57r4-5mwx: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-5104 [CRITICAL] CWE-119 GHSA-859j-57r4-5mwx: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3095, CVE-2015-5087, CVE-2015-5094, CVE-2015-5100, CVE-2015-5102, CVE-2015-5103, and CVE-2015-5115.
GHSA
GHSA-xgq4-mggp-p859: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-5087 [CRITICAL] CWE-119 GHSA-xgq4-mggp-p859: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3095, CVE-2015-5094, CVE-2015-5100, CVE-2015-5102, CVE-2015-5103, CVE-2015-5104, and CVE-2015-5115.
GHSA
GHSA-57r2-cmqp-xp55: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-5100 [CRITICAL] CWE-119 GHSA-57r2-cmqp-xp55: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3095, CVE-2015-5087, CVE-2015-5094, CVE-2015-5102, CVE-2015-5103, CVE-2015-5104, and CVE-2015-5115.
GHSA
GHSA-gfcx-q3c4-f4p5: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-5102 [CRITICAL] CWE-119 GHSA-gfcx-q3c4-f4p5: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3095, CVE-2015-5087, CVE-2015-5094, CVE-2015-5100, CVE-2015-5103, CVE-2015-5104, and CVE-2015-5115.
GHSA
GHSA-5jvx-wxpf-6w9q: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-3095 [CRITICAL] CWE-119 GHSA-5jvx-wxpf-6w9q: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5087, CVE-2015-5094, CVE-2015-5100, CVE-2015-5102, CVE-2015-5103, CVE-2015-5104, and CVE-2015-5115.
Project0
One font vulnerability to rule them all #1: Introducing the BLEND vulnerability - Project Zero
project_zero·2015-07-01·CVSS 4.3
CVE-2015-0074 [MEDIUM] One font vulnerability to rule them all #1: Introducing the BLEND vulnerability - Project Zero
Posted by Mateusz Jurczyk of Google Project Zero
Last month, I presented parts of my PostScript font security research at the REcon security conference in Montreal, in a talk titled “One font vulnerability to rule them all: A story of cross-software ownage, shared codebases and advanced exploitation”. This talk discussed the exploitation process of a vulnerability found in the implementation of a BLEND Charstring instruction, discovered in a user-mode Adobe Reader’s CoolType library and a kernel-mode Adobe Type Manager Font Driver (ATMFD.DLL) used by Windows, both of which are responsible for supporting Type 1 and OpenType fonts in the Reader and system GDI environments. This research was performed as part of my Project Zero work, and more generally resulted in a multitude of vulnerabili
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-15
Published