CVE-2018-5017
published 2018-07-20CVE-2018-5017: Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read…
PriorityP433medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
8.43%
94.4th percentile
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | 15.006.30060 – 15.006.30418 | — |
| adobe | acrobat_dc | 15.008.20082 – 18.011.20040 | — |
| adobe | acrobat_dc | 17.011.30059 – 17.011.30080 | — |
| adobe | acrobat_reader_dc | 15.006.30060 – 15.006.30418 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 18.011.20040 | — |
| adobe | acrobat_reader_dc | 17.011.30059 – 17.011.30080 | — |
| apache | zookeeper | >= 0 < 3.4.5+dfsg-1ubuntu0.1~esm1 | 3.4.5+dfsg-1ubuntu0.1~esm1 |
| apache | zookeeper | >= 0 < 3.4.8-1ubuntu0.1~esm1 | 3.4.8-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hp62-5mxj-4w3q: Adobe Acrobat and Reader 2018
ghsa_unreviewed·2022-05-14
CVE-2018-5017 [MEDIUM] CWE-125 GHSA-hp62-5mxj-4w3q: Adobe Acrobat and Reader 2018
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
OSV
zookeeper vulnerabilities
osv·2021-03-15·CVSS 8.1
CVE-2016-5017 zookeeper vulnerabilities
zookeeper vulnerabilities
It was discovered that Apache ZooKeeper incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2016-5017)
It was discovered that Apache ZooKeeper incorrectly implemented "wchp/wchc"
commands. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-5637)
It was discovered that Apache Zookeeper incorrectly handled clusters. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected Ubuntu 16.04 ESM. (CVE-2018-8012)
No detection rules found.
No public exploits indexed.
2018-07-20
Published