CVE-2015-4449
published 2015-07-15CVE-2015-4449: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat…
PriorityP428medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.64%
90.8th percentile
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4450, CVE-2015-5088, CVE-2015-5089, and CVE-2015-5092.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | >= 10.0 < 10.1.15 | 10.1.15 |
| adobe | acrobat | 10.0 – 10.1.14 | — |
| adobe | acrobat | >= 11.0.0 < 11.0.12 | 11.0.12 |
| adobe | acrobat | 11.0.0 – 11.0.11 | — |
| adobe | acrobat_dc | >= 15.006.30033 < 15.006.30060 | 15.006.30060 |
| adobe | acrobat_dc | >= 15.007.20033 < 15.008.20082 | 15.008.20082 |
| adobe | acrobat_reader | >= 10.0 < 10.1.15 | 10.1.15 |
| adobe | acrobat_reader | 10.0 – 10.1.14 | — |
| adobe | acrobat_reader | >= 11.0.0 < 11.0.12 | 11.0.12 |
| adobe | acrobat_reader | 11.0.0 – 11.0.11 | — |
| adobe | acrobat_reader_dc | >= 15.006.30033 < 15.006.30060 | 15.006.30060 |
| adobe | acrobat_reader_dc | >= 15.007.20033 < 15.008.20082 | 15.008.20082 |
| openldap | openldap | >= 0 < 2.4.31-1+nmu2ubuntu8.1 | 2.4.31-1+nmu2ubuntu8.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2g76-9p9p-qv6g: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2014-8450 [MEDIUM] CWE-200 GHSA-2g76-9p9p-qv6g: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-4449, CVE-2015-4450, CVE-2015-5088, CVE-2015-5089, and CVE-2015-5092.
GHSA
GHSA-mr95-v9f6-rhv6: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2015-4449 [MEDIUM] CWE-200 GHSA-mr95-v9f6-rhv6: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4450, CVE-2015-5088, CVE-2015-5089, and CVE-2015-5092.
GHSA
GHSA-9jcg-6rp8-r9jr: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2015-5092 [MEDIUM] CWE-200 GHSA-9jcg-6rp8-r9jr: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4449, CVE-2015-4450, CVE-2015-5088, and CVE-2015-5089.
GHSA
GHSA-c7vw-5hm7-6vqc: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2015-5089 [MEDIUM] CWE-200 GHSA-c7vw-5hm7-6vqc: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4449, CVE-2015-4450, CVE-2015-5088, and CVE-2015-5092.
GHSA
GHSA-whpc-4c93-2f38: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2015-4450 [MEDIUM] CWE-200 GHSA-whpc-4c93-2f38: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4449, CVE-2015-5088, CVE-2015-5089, and CVE-2015-5092.
GHSA
GHSA-jcx9-g3h6-rhr2: Adobe Reader and Acrobat 10
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2015-5088 [MEDIUM] CWE-200 GHSA-jcx9-g3h6-rhr2: Adobe Reader and Acrobat 10
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4449, CVE-2015-4450, CVE-2015-5089, and CVE-2015-5092.
OSV
openldap vulnerabilities
osv·2015-05-26·CVSS 2.6
CVE-2012-1164 openldap vulnerabilities
openldap vulnerabilities
It was discovered that OpenLDAP incorrectly handled certain search queries
that returned empty attributes. A remote attacker could use this issue to
cause OpenLDAP to assert, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2012-1164)
Michael Vishchers discovered that OpenLDAP improperly counted references
when the rwm overlay was used. A remote attacker could use this issue to
cause OpenLDAP to crash, resulting in a denial of service. (CVE-2013-4449)
It was discovered that OpenLDAP incorrectly handled certain empty attribute
lists in search requests. A remote attacker could use this issue to cause
OpenLDAP to crash, resulting in a denial of service. (CVE-2015-1545)
No detection rules found.
No public exploits indexed.
2015-07-15
Published