CVE-2018-12760
published 2018-07-20CVE-2018-12760: Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write…
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
8.50%
94.5th percentile
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | 15.006.30060 – 15.006.30418 | — |
| adobe | acrobat_dc | 15.008.20082 – 18.011.20040 | — |
| adobe | acrobat_dc | 17.011.30059 – 17.011.30080 | — |
| adobe | acrobat_reader_dc | 15.006.30060 – 15.006.30418 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 18.011.20040 | — |
| adobe | acrobat_reader_dc | 17.011.30059 – 17.011.30080 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenNMS Horizon RCE via Unsafe Deserialization
ghsa·2022-05-24
CVE-2020-12760 [HIGH] CWE-502 OpenNMS Horizon RCE via Unsafe Deserialization
OpenNMS Horizon RCE via Unsafe Deserialization
An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code execution for any authenticated channel user regardless of its assigned permissions.
GHSA
GHSA-92jh-43m5-5hp6: Adobe Acrobat and Reader 2018
ghsa_unreviewed·2022-05-14
CVE-2018-12760 [CRITICAL] CWE-787 GHSA-92jh-43m5-5hp6: Adobe Acrobat and Reader 2018
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
No detection rules found.
No public exploits indexed.
2018-07-20
Published