(CVE-2019-8220) Adobe Reader CLstBxField Use-after-Free

CVE: CVE-2019-8220 Tested Versions: Adobe Acrobat and Reader DC versions 2019.012.20040 and earlier Product URL(s): https://acrobat.adobe.com/us/en/acrobat.html https://get.adobe.com/reader/ Description of the vulnerability Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage files in Portable Document Format (PDF). Both Adobe Reader and Acrobat DC share the same DigSig.api plugin: Image path: C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\plug_ins\DigSig.api File Version Number: 19....

October 15, 2019 · 4 min · Ta Dinh Sung

(CVE-2019-8221) Adobe Reader Type Confusion in getColorConvertAction

CVE: CVE-2019-8221 Tested Versions: Acrobat DC version 2019.008.20064 (Windows 10 64-bit) Product URL(s): https://acrobat.adobe.com/us/en/acrobat.html https://get.adobe.com/reader/ Description of the vulnerability Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage files in Portable Document Format (PDF). Both Adobe Reader and Acrobat DC share the same Escript.api plugin: Image path: C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\plug_ins\EScript.api Image name: EScript....

October 15, 2019 · 3 min · Ta Dinh Sung

(CVE-2019-1250) Microsoft Jet database Record::IsNull Memory Corruption

CVE: CVE-2019-1250 Tested Versions: Windows 10 version 1903 and below Windows 7 Product URL(s): https://www.microsoft.com The Microsoft Jet Database Engine (also Microsoft JET Engine or simply Jet) is a database engine on which several Microsoft products have been built. JET stands for Joint Engine Technology. Microsoft Access and Visual Basic have used Jet as their underlying database engine. Vulnerability The vulnerable DLL msrd3x40.dll is a component in versions from Windows 7 to Windows 10....

September 10, 2019 · 5 min · Shi Ji (@Puzzorsj) & Meysam Firouzi

(CVE-2019-8011) Acrobat Reader DC 2d.x3d!_LoadTIFF() Out-of-Bounds Read

CVE: CVE-2019-8011 Tested Versions: Adobe Reader DC 2019.010.20099 Product URL(s): https://acrobat.adobe.com/us/en/acrobat.html https://get.adobe.com/reader/ Description of the vulnerability Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage files in Portable Document Format (PDF). It provides compatibility to the ECMA-363 Standard (Universal 3D File Format) via 3difr.x3d, 2d.x3d and rt3d.dll, which allow viewing embedded 3D contents in PDF files....

August 13, 2019 · 4 min · Wei Lei

(CVE-2019-8018) Acrobat Reader DC 2d.x3d!_LoadRGB() OOB Read in TRGB::expandrow()

CVE: CVE-2019-8018 Tested Versions: Adobe Reader DC 2019.010.20099 Product URL(s): https://acrobat.adobe.com/us/en/acrobat.html https://get.adobe.com/reader/ Description of the vulnerability Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage files in Portable Document Format (PDF). It provides compatibility to the ECMA-363 Standard (Universal 3D File Format) via 3difr.x3d, 2d.x3d and rt3d.dll, which allow viewing embedded 3D contents in PDF files....

August 13, 2019 · 5 min · Wei Lei

(CVE-2019-8038) Adobe Acrobat/Reader CTextWidget Use-after-Free

CVE: CVE-2019-8038 Tested Versions: Adobe Acrobat and Reader versions 2019.012.20035 and earlier Product URL(s): https://acrobat.adobe.com/us/en/acrobat.html https://get.adobe.com/reader/ Description of the vulnerability Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage files in Portable Document Format (PDF). The basic Acrobat Reader, available for several desktop and mobile platforms, is freeware; it supports viewing, printing and annotating of PDF files....

June 20, 2019 · 5 min · Phan Thanh Duy (@PTDuy)

(CVE-2019-8039) Adobe Acrobat/Reader CTextField Use-after-Free

CVE: CVE-2019-8039 Tested Versions: Adobe Acrobat and Reader versions 2019.012.20035 and earlier Product URL(s): https://acrobat.adobe.com/us/en/acrobat.html https://get.adobe.com/reader/ Description of the vulnerability Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage files in Portable Document Format (PDF). The basic Acrobat Reader, available for several desktop and mobile platforms, is freeware; it supports viewing, printing and annotating of PDF files....

June 20, 2019 · 3 min · Phan Thanh Duy (@PTDuy)