CVE-2015-4447
published 2015-07-15CVE-2015-4447: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.65%
93.9th percentile
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | >= 10.0 < 10.1.15 | 10.1.15 |
| adobe | acrobat | 10.0 – 10.1.14 | — |
| adobe | acrobat | >= 11.0.0 < 11.0.12 | 11.0.12 |
| adobe | acrobat | 11.0.0 – 11.0.11 | — |
| adobe | acrobat_dc | >= 15.006.30033 < 15.006.30060 | 15.006.30060 |
| adobe | acrobat_dc | >= 15.007.20033 < 15.008.20082 | 15.008.20082 |
| adobe | acrobat_reader | >= 10.0 < 10.1.15 | 10.1.15 |
| adobe | acrobat_reader | 10.0 – 10.1.14 | — |
| adobe | acrobat_reader | >= 11.0.0 < 11.0.12 | 11.0.12 |
| adobe | acrobat_reader | 11.0.0 – 11.0.11 | — |
| adobe | acrobat_reader_dc | >= 15.006.30033 < 15.006.30060 | 15.006.30060 |
| adobe | acrobat_reader_dc | >= 15.007.20033 < 15.008.20082 | 15.008.20082 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.8 | 2.9.1+dfsg1-3ubuntu4.8 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1ubuntu0.1 | 2.9.3+dfsg1-1ubuntu0.1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m272-q487-qcjg: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-5086 [CRITICAL] GHSA-m272-q487-qcjg: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4447, CVE-2015-4451, CVE-2015-4452, and CVE-2015-5085.
GHSA
GHSA-pp5m-5cvr-qhx9: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-4451 [CRITICAL] GHSA-pp5m-5cvr-qhx9: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4447, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.
GHSA
GHSA-c3cx-8mvg-g7xg: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-4435 [CRITICAL] GHSA-c3cx-8mvg-g7xg: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4447, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.
GHSA
GHSA-2wmg-qmv3-pmvc: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-4447 [CRITICAL] GHSA-2wmg-qmv3-pmvc: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.
GHSA
GHSA-4h9v-63rw-p289: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-4441 [CRITICAL] GHSA-4h9v-63rw-p289: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4445, CVE-2015-4447, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.
GHSA
GHSA-629f-ccmh-g32f: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-5085 [CRITICAL] GHSA-629f-ccmh-g32f: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4447, CVE-2015-4451, CVE-2015-4452, and CVE-2015-5086.
GHSA
GHSA-7hm7-46w7-2gvq: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-4438 [CRITICAL] GHSA-7hm7-46w7-2gvq: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4441, CVE-2015-4445, CVE-2015-4447, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.
GHSA
GHSA-6h4g-36qw-4762: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-4452 [CRITICAL] GHSA-6h4g-36qw-4762: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4447, CVE-2015-4451, CVE-2015-5085, and CVE-2015-5086.
GHSA
GHSA-mh8f-3q3j-jrqw: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-4445 [CRITICAL] GHSA-mh8f-3q3j-jrqw: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4447, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.
OSV
libxml2 vulnerabilities
osv·2016-06-06·CVSS 7.5
CVE-2015-8806 libxml2 vulnerabilities
libxml2 vulnerabilities
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could possibly cause libxml2 to
crash, resulting in a denial of service. (CVE-2015-8806, CVE-2016-2073,
CVE-2016-3627, CVE-2016-3705, CVE-2016-4447)
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-1762, CVE-2016-1834)
Mateusz Jurczyk discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
No detection rules found.
No public exploits indexed.
2015-07-15
Published