vciy

Adobe Acrobat Reader: 61 records in one advisory

61 records announced together, published 2017-12-09, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb17-36.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

38 of 61 records name something of its own. For the other 23, held sources say the same thing about each.

Most commonly mapped weakness across the batch: Out-of-bounds Read.

What this page does not cover

This batch is 61 of the 67 records that cite the same advisory. The other 6 are different findings announced alongside it.

None of those 6 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2017-16360creating structureUse After Free
CVE-2017-16361xfdfSecurity Bypass
CVE-2017-16362makeaccesible which sometimes triggersOut-of-bounds Read
CVE-2017-16363character codes representationsBuffer Over-read
CVE-2017-16364number dictionary entriesUntrusted Pointer Dereference
CVE-2017-16365true type2 corrupted cmapBuffer Over-read
CVE-2017-16366acropdfSecurity Bypass
CVE-2017-16367attackers exploitType Confusion
CVE-2017-16368stack-based condition unicode stringBuffer Overflow / Underflow
CVE-2017-16369same origin policy affectingSecurity Bypass
CVE-2017-16370out-of-rangeOut-of-bounds Read
CVE-2017-16371no title heldUntrusted Pointer Dereference
CVE-2017-16372no title heldUntrusted Pointer Dereference
CVE-2017-16373belong relevantUntrusted Pointer Dereference
CVE-2017-16374streamBuffer Over-read
CVE-2017-16375javasscriptUntrusted Pointer Dereference
CVE-2017-16376no title heldOut-of-bounds Read
CVE-2017-16377main dll thereforeAccess of Uninitialized Pointer
CVE-2017-16378ast threadAccess of Uninitialized Pointer
CVE-2017-16379renderingType Confusion
CVE-2017-16380file-type extension maintains bothSecurity Bypass
CVE-2017-16381no title heldBuffer Access with Incorrect Length Value
CVE-2017-16382no title heldOut-of-bounds Read
CVE-2017-16383no title heldHeap Overflow
CVE-2017-16384exif pngBuffer Over-read
CVE-2017-16385no title heldBuffer Access with Incorrect Length Value
CVE-2017-16386xps2pdfBuffer Over-read
CVE-2017-16387jpeg2000 codecBuffer Over-read
CVE-2017-16388no title heldUse After Free
CVE-2017-16389no title heldUse After Free
CVE-2017-16390no title heldUse After Free
CVE-2017-16391printing writeImproper Validation of Array Index
CVE-2017-16392segmentBuffer Access with Incorrect Length Value
CVE-2017-16393no title heldUse After Free
CVE-2017-16394no title heldOut-of-bounds Read
CVE-2017-16395emr_stretchdibitsBuffer Access with Incorrect Length Value
CVE-2017-16396no title heldBuffer Access with Incorrect Length Value
CVE-2017-16397no title heldOut-of-bounds Read
CVE-2017-16398no title heldUse After Free
CVE-2017-16399no title heldOut-of-bounds Read
CVE-2017-16400parserOut-of-bounds Read
CVE-2017-16401specificallyOut-of-bounds Read
CVE-2017-16402no title heldOut-of-bounds Read
CVE-2017-16403processesOut-of-bounds Read
CVE-2017-16404no title heldOut-of-bounds Read
CVE-2017-16405acrobat's page displayOut-of-bounds Read
CVE-2017-16406program incompatible leadingType Confusion
CVE-2017-16407emr_bitblt recordOut-of-bounds Write
CVE-2017-16408no title heldOut-of-bounds Read
CVE-2017-16409displayingOut-of-bounds Read
CVE-2017-16410gifImproper Validation of Array Index
CVE-2017-16411related hashUntrusted Pointer Dereference
CVE-2017-16412resourceOut-of-bounds Read
CVE-2017-16413no title heldOut-of-bounds Write
CVE-2017-16414formOut-of-bounds Read
CVE-2017-16415encodingsOut-of-bounds Write
CVE-2017-16416no title heldOut-of-bounds Write
CVE-2017-16417no title heldOut-of-bounds Read
CVE-2017-16418no title heldOut-of-bounds Read
CVE-2017-16419stack exhaustion problem doesStackExhaustion
CVE-2017-16420annotationOut-of-bounds Read

61 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.