Vulnerabilities > Adobe > Acrobat DC > High

DATE CVE VULNERABILITY TITLE RISK
2017-01-11 CVE-2017-2963 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to handling of the color profile in a TIFF file.
local
low complexity
adobe CWE-119
7.8
2017-01-11 CVE-2017-2962 Incorrect Type Conversion or Cast vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable type confusion vulnerability in the XSLT engine related to localization functionality.
local
low complexity
adobe CWE-704
7.8
2017-01-11 CVE-2017-2961 Use After Free vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the XFA engine, related to validation functionality.
local
low complexity
adobe CWE-416
7.8
2017-01-11 CVE-2017-2960 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of EXIF metadata.
local
low complexity
adobe CWE-119
7.8
2017-01-11 CVE-2017-2959 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the image conversion engine, related to parsing of color profile metadata.
local
low complexity
adobe CWE-119
7.8
2017-01-11 CVE-2017-2958 Use After Free vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine.
local
low complexity
adobe CWE-416
7.8
2017-01-11 CVE-2017-2957 Use After Free vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine, related to collaboration functionality.
local
low complexity
adobe CWE-416
7.8
2017-01-11 CVE-2017-2956 Use After Free vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine, related to manipulation of the navigation pane.
local
low complexity
adobe CWE-416
7.8
2017-01-11 CVE-2017-2955 Use After Free vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine.
local
low complexity
adobe CWE-416
7.8
2017-01-11 CVE-2017-2954 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module when handling malformed TIFF images.
local
low complexity
adobe CWE-119
7.8