CVE-2020-3802
published 2020-03-25CVE-2020-3802: Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.53%
90.5th percentile
Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | >= 15.006.30060 < 15.006.30518 | 15.006.30518 |
| adobe | acrobat_dc | >= 15.008.20082 < 20.006.20042 | 20.006.20042 |
| adobe | acrobat_dc | >= 17.011.30059 < 17.011.30166 | 17.011.30166 |
| adobe | acrobat_reader_dc | >= 15.006.30060 < 15.006.30518 | 15.006.30518 |
| adobe | acrobat_reader_dc | >= 15.008.20082 < 20.006.20042 | 20.006.20042 |
| adobe | acrobat_reader_dc | >= 17.011.30059 < 17.011.30166 | 17.011.30166 |
| adobe | adobe_acrobat_and_reader | — | — |
| github.com | ibax-io_go-ibax | >= 0 < 1.4.2 | 1.4.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBAX go-ibax vulnerable to SQL injection
ghsa·2022-11-01
CVE-2022-3802 [HIGH] CWE-89 IBAX go-ibax vulnerable to SQL injection
IBAX go-ibax vulnerable to SQL injection
SQL Injection vulnerability in `/packages/api/database.go` of go-ibax via `where` parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects versions starting from commits on Jul 18, 2020.
GHSA
GHSA-x4v7-c63g-mh6m: Adobe Acrobat and Reader versions 2020
ghsa_unreviewed·2022-05-24
CVE-2020-3802 [MEDIUM] CWE-416 GHSA-x4v7-c63g-mh6m: Adobe Acrobat and Reader versions 2020
Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
No detection rules found.
No public exploits indexed.
2020-03-25
Published