CVE-2018-16042
medium · 6.5Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a security bypass vulnerability. Successful exploitation could lead to information disclosure.
6.5
CVSS
82.4%
EPSS (exploit prob.)
100th
EPSS percentile
2019-01-18
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weaknesses
CWE-347
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | acrobat_dc | >= 15.006.30060, <= 15.006.30457 |
| adobe | acrobat_dc | >= 15.008.20082, <= 19.008.20081 |
| adobe | acrobat_dc | >= 17.011.30056, <= 17.011.30106 |
| adobe | acrobat_reader_dc | >= 15.006.30060, <= 15.006.30457 |
| adobe | acrobat_reader_dc | >= 15.008.20082, <= 19.008.20081 |
| adobe | acrobat_reader_dc | >= 17.011.30059, <= 17.011.30106 |
| adobe | reader | 11.0.10 |
| adobe | reader | 11.0.23 |
| iskysoft | pdf_editor_6 | 6.4.2.3521 |
| iskysoft | pdfelement6 | 6.8.0.3523 |
| iskysoft | pdfelement6 | 6.8.4.3921 |
| microsoft | windows | all versions |
| adobe | acrobat_dc | >= 15.006.30060, <= 15.006.30456 |
| adobe | acrobat_dc | >= 15.008.20082, <= 19.008.20080 |
| adobe | acrobat_dc | >= 17.011.30056, <= 17.011.30105 |
| adobe | acrobat_reader_dc | >= 15.006.30060, <= 15.006.30456 |
| adobe | acrobat_reader_dc | >= 15.008.20082, <= 19.008.20080 |
| adobe | acrobat_reader_dc | >= 17.011.30059, <= 17.011.30105 |
| adobe | reader | 11.0.10 |
| adobe | reader | 11.0.23 |
| iskysoft | pdf_editor_6 | 6.6.2.3315 |
| iskysoft | pdf_editor_6 | 6.7.6.3399 |
| iskysoft | pdfelement6 | 6.7.1.3355 |
| iskysoft | pdfelement6 | 6.7.6.3399 |
| apple | mac_os_x | all versions |
| adobe | acrobat_dc | >= 15.006.30060, <= 15.006.30456 |
| adobe | acrobat_dc | >= 15.008.20082, <= 19.008.20080 |
| adobe | acrobat_dc | >= 17.011.30056, <= 17.011.30105 |
| adobe | acrobat_reader_dc | >= 15.006.30060, <= 15.006.30456 |
| adobe | acrobat_reader_dc | >= 15.008.20082, <= 19.008.20080 |
| adobe | acrobat_reader_dc | >= 17.011.30059, <= 17.011.30105 |
| linux | linux_kernel | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/106159
- https://helpx.adobe.com/security/products/acrobat/apsb18-41.html
- https://pdf-insecurity.org/signature/evaluation_2018.html
- https://pdf-insecurity.org/signature/signature.html
- https://www.pdfa.org/recently-identified-pdf-digital-signature-vulnerabilities/
- http://www.securityfocus.com/bid/106159
- https://helpx.adobe.com/security/products/acrobat/apsb18-41.html
- https://pdf-insecurity.org/signature/evaluation_2018.html
- https://pdf-insecurity.org/signature/signature.html
- https://www.pdfa.org/recently-identified-pdf-digital-signature-vulnerabilities/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-16042