Vulnerabilities > CVE-2016-1111 - Double Free Remote Code Execution vulnerability in Adobe Acrobat and Reader

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
adobe
apple
microsoft
nessus

Summary

Double free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via a crafted Graphics State dictionary. <a href="http://cwe.mitre.org/data/definitions/415.html">CWE-415: Double Free</a>

Vulnerable Configurations

Part Description Count
Application
Adobe
232
OS
Apple
1
OS
Microsoft
1

Nessus

  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_ADOBE_READER_APSB16-02.NASL
    descriptionThe version of Adobe Reader installed on the remote Mac OS X host is a version prior to 11.0.14, 15.006.30119, or 15.010.20056. It is, therefore, affected by multiple vulnerabilities : - Multiple use-after-free errors exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0932, CVE-2016-0934, CVE-2016-0937, CVE-2016-0940, CVE-2016-0941) - Multiple memory corruption issues exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0931, CVE-2016-0933, CVE-2016-0936, CVE-2016-0938, CVE-2016-0939, CVE-2016-0942, CVE-2016-0944, CVE-2016-0945, CVE-2016-0946) - Multiple double-free errors exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0935, CVE-2016-1111) - A flaw exists in the Global JavaScript API that allows a remote attacker to bypass restrictions and execute arbitrary code. (CVE-2016-0943) - A flaw exists in the download manager related to the directory search path used to find resources. A remote attacker can exploit this execute arbitrary code. (CVE-2016-0947) Note that Nessus has not tested for these issues but has instead relied only on the application
    last seen2020-06-01
    modified2020-06-02
    plugin id87920
    published2016-01-14
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/87920
    titleAdobe Reader < 11.0.14 / 15.006.30119 / 15.010.20056 Multiple Vulnerabilities (APSB16-02) (Mac OS X)
  • NASL familyWindows
    NASL idADOBE_READER_APSB16-02.NASL
    descriptionThe version of Adobe Reader installed on the remote host is a version prior to 11.0.14, 15.006.30119, or 15.010.20056. It is, therefore, affected by multiple vulnerabilities : - Multiple use-after-free errors exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0932, CVE-2016-0934, CVE-2016-0937, CVE-2016-0940, CVE-2016-0941) - Multiple memory corruption issues exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0931, CVE-2016-0933, CVE-2016-0936, CVE-2016-0938, CVE-2016-0939, CVE-2016-0942, CVE-2016-0944, CVE-2016-0945, CVE-2016-0946) - Multiple double-free errors exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0935, CVE-2016-1111) - A flaw exists in the Global JavaScript API that allows a remote attacker to bypass restrictions and execute arbitrary code. (CVE-2016-0943) - A flaw exists in the download manager related to the directory search path used to find resources. A remote attacker can exploit this execute arbitrary code. (CVE-2016-0947)
    last seen2020-06-01
    modified2020-06-02
    plugin id87918
    published2016-01-14
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/87918
    titleAdobe Reader < 11.0.14 / 15.006.30119 / 15.010.20056 Multiple Vulnerabilities (APSB16-02)
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_ADOBE_ACROBAT_APSB16-02.NASL
    descriptionThe version of Adobe Acrobat installed on the remote Mac OS X host is a version prior to 11.0.14, 15.006.30119, or 15.010.20056. It is, therefore, affected by multiple vulnerabilities : - Multiple use-after-free errors exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0932, CVE-2016-0934, CVE-2016-0937, CVE-2016-0940, CVE-2016-0941) - Multiple memory corruption issues exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0931, CVE-2016-0933, CVE-2016-0936, CVE-2016-0938, CVE-2016-0939, CVE-2016-0942, CVE-2016-0944, CVE-2016-0945, CVE-2016-0946) - Multiple double-free errors exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0935, CVE-2016-1111) - A flaw exists in the Global JavaScript API that allows a remote attacker to bypass restrictions and execute arbitrary code. (CVE-2016-0943) - A flaw exists in the download manager related to the directory search path used to find resources. A remote attacker can exploit this execute arbitrary code. (CVE-2016-0947) Note that Nessus has not tested for these issues but has instead relied only on the application
    last seen2020-06-01
    modified2020-06-02
    plugin id87919
    published2016-01-14
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/87919
    titleAdobe Acrobat < 11.0.14 / 15.006.30119 / 15.010.20056 Multiple Vulnerabilities (APSB16-02) (Mac OS X)
  • NASL familyWindows
    NASL idADOBE_ACROBAT_APSB16-02.NASL
    descriptionThe version of Adobe Acrobat installed on the remote Windows host is a version prior to 11.0.14, 15.006.30119, or 15.010.20056. It is, therefore, affected by multiple vulnerabilities : - Multiple use-after-free errors exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0932, CVE-2016-0934, CVE-2016-0937, CVE-2016-0940, CVE-2016-0941) - Multiple memory corruption issues exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0931, CVE-2016-0933, CVE-2016-0936, CVE-2016-0938, CVE-2016-0939, CVE-2016-0942, CVE-2016-0944, CVE-2016-0945, CVE-2016-0946) - Multiple double-free errors exist that allow a remote attacker to execute arbitrary code. (CVE-2016-0935, CVE-2016-1111) - A flaw exists in the Global JavaScript API that allows a remote attacker to bypass restrictions and execute arbitrary code. (CVE-2016-0943) - A flaw exists in the download manager related to the directory search path used to find resources. A remote attacker can exploit this execute arbitrary code. (CVE-2016-0947) Note that Nessus has not tested for these issues but has instead relied only on the application
    last seen2020-06-01
    modified2020-06-02
    plugin id87917
    published2016-01-14
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/87917
    titleAdobe Acrobat < 11.0.14 / 15.006.30119 / 15.010.20056 Multiple Vulnerabilities (APSB16-02)