KLA10838
Multiple vulnerabilities in Adobe Acrobat & Reader
Updated: 06/01/2019
Detect date
?
07/12/2016
Severity
?
Critical
Description

Multiple serious vulnerabilities have been found in Adobe products. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions or cause a denial of service.

Below is a complete list of vulnerabilities

  1. Integer overflow, use-after-free, buffer overflow and multiple memory corruption vulnerabilities can be exploited remotely to execute arbitrary code;
  2. An unknown vulnerability at Javascript API can be exploited remotely to bypass security restrictions.
  3. Memory corruption vulnerability can be exploited remotely to cause denial of service.
Affected products

Adobe Acrobat DC Continuous versions earlier than 15.017.20050
Adobe Acrobat Reader DC Continuous versions earlier than 15.017.20050
Adobe Acrobat DC Classic versions earlier than 15.006.30198
Adobe Acrobat Reader DC Classic versions earlier than 15.006.30198
Adobe Acrobat XI versions earlier than 11.0.17
Adobe Reader XI versions earlier than 11.0.17

Solution

Update to the latest version
Get Adobe Reader

Original advisories

Adobe security advisory

Impacts
?
ACE 
[?]

DoS 
[?]

SB 
[?]
Related products
Adobe Reader XI
Adobe Acrobat XI
Adobe Acrobat Reader DC Continuous
Adobe Acrobat Reader DC Classic
Adobe Acrobat DC Continuous
Adobe Acrobat DC Classic
CVE-IDS
?
CVE-2016-42556.8High
CVE-2016-425410.0Critical
CVE-2016-425210.0Critical
CVE-2016-425110.0Critical
CVE-2016-425010.0Critical
CVE-2016-42026.8High
CVE-2016-420310.0Critical
CVE-2016-420410.0Critical
CVE-2016-420510.0Critical
CVE-2016-420610.0Critical
CVE-2016-420710.0Critical
CVE-2016-420910.0Critical
CVE-2016-421010.0Critical
CVE-2016-419110.0Critical
CVE-2016-419210.0Critical
CVE-2016-419310.0Critical
CVE-2016-419410.0Critical
CVE-2016-41956.8High
CVE-2016-41966.8High
CVE-2016-41976.8High
CVE-2016-41986.8High
CVE-2016-41996.8High
CVE-2016-42006.8High
CVE-2016-420110.0Critical
CVE-2016-426510.0Critical
CVE-2016-426610.0Critical
CVE-2016-426710.0Critical
CVE-2016-426810.0Critical
CVE-2016-426910.0Critical
CVE-2016-427010.0Critical
CVE-2016-420810.0Critical
CVE-2016-693810.0Critical
CVE-2016-693710.0Critical
CVE-2016-421110.0Critical
CVE-2016-421210.0Critical
CVE-2016-421310.0Critical
CVE-2016-421410.0Critical
CVE-2016-421510.0Critical