CVE-2017-3055
published 2017-04-12CVE-2017-3055: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in JPEG…
PriorityP346high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
14.45%
96.2th percentile
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in JPEG 2000 parsing of the fragment list tag. Successful exploitation could lead to arbitrary code execution.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 11.0.19 | — |
| adobe | acrobat_dc | <= 15.006.30280 | — |
| adobe | acrobat_dc | <= 15.023.20070 | — |
| adobe | acrobat_reader_dc | <= 15.006.30280 | — |
| adobe | acrobat_reader_dc | <= 15.023.20070 | — |
| adobe | reader | <= 11.0.19 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h5cw-j7vg-mv6r: Adobe Acrobat Reader versions 11
ghsa_unreviewed·2022-05-17
CVE-2017-3055 [HIGH] CWE-119 GHSA-h5cw-j7vg-mv6r: Adobe Acrobat Reader versions 11
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in JPEG 2000 parsing of the fragment list tag. Successful exploitation could lead to arbitrary code execution.
Citrix
Citrix Security Bulletin CTX220138
vendor_citrix·CVSS 7.5
CVE-2017-9231 [HIGH] Citrix Security Bulletin CTX220138
Citrix Security Bulletin CTX220138
CVE References: CVE-2017-9231, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX220112
vendor_citrix·CVSS 7.5
CVE-2015-7704 [HIGH] Citrix Security Bulletin CTX220112
Citrix Security Bulletin CTX220112
CVE References: CVE-2015-7704, CVE-2015-7705, CVE-2017-5572, CVE-2017-5573, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX220112
vendor_citrix·CVSS 6.5
CVE-2017-5572 [MEDIUM] Citrix Security Bulletin CTX220112
Citrix Security Bulletin CTX220112
CVE References: CVE-2017-5572, CVE-2017-5573, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX225941
vendor_citrix·CVSS 8.8
CVE-2017-12134 [HIGH] Citrix Security Bulletin CTX225941
Citrix Security Bulletin CTX225941
CVE References: CVE-2017-12134, CVE-2017-12135, CVE-2017-12136, CVE-2017-12137, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX220771
vendor_citrix·CVSS 9.1
CVE-2017-2615 [CRITICAL] Citrix Security Bulletin CTX220771
Citrix Security Bulletin CTX220771
CVE References: CVE-2017-2615, CVE-2017-2620, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX225990
vendor_citrix·CVSS 9.8
CVE-2017-6316 [CRITICAL] Citrix Security Bulletin CTX225990
Citrix Security Bulletin CTX225990
CVE References: CVE-2017-6316, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX220329
vendor_citrix·CVSS 5.9
CVE-2016-0270 [MEDIUM] Citrix Security Bulletin CTX220329
Citrix Security Bulletin CTX220329
CVE References: CVE-2016-0270, CVE-2017-5933, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX220329
vendor_citrix·CVSS 5.9
CVE-2017-5933 [MEDIUM] Citrix Security Bulletin CTX220329
Citrix Security Bulletin CTX220329
CVE References: CVE-2017-5933, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX227928
vendor_citrix·CVSS 7.2
CVE-2017-14602 [HIGH] Citrix Security Bulletin CTX227928
Citrix Security Bulletin CTX227928
CVE References: CVE-2017-14602, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX222657
vendor_citrix·CVSS 8.8
CVE-2017-7219 [HIGH] Citrix Security Bulletin CTX222657
Citrix Security Bulletin CTX222657
CVE References: CVE-2017-7219, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX228091
vendor_citrix·CVSS 7.2
CVE-2017-14602 [HIGH] Citrix Security Bulletin CTX228091
Citrix Security Bulletin CTX228091
CVE References: CVE-2017-14602, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/97549http://www.securitytracker.com/id/1038228https://helpx.adobe.com/security/products/acrobat/apsb17-11.htmlhttp://www.zerodayinitiative.com/advisories/ZDI-17-280/http://www.securityfocus.com/bid/97549http://www.securitytracker.com/id/1038228https://helpx.adobe.com/security/products/acrobat/apsb17-11.html
2017-04-12
Published