vciy

Adobe Acrobat and Reader: 87 records in one advisory

87 records announced together, published between 2018-10-12 and 2019-01-18, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb18-30.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

3 of 87 records name something of its own. For the other 84, held sources say the same thing about each.

Most commonly mapped weakness across the batch: Out-of-bounds read.

What this page does not cover

Every record citing this advisory is on this page.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

35 of these came from one Check Point fuzzing run against Reader's image parser

Adobe published APSB18-30 on 1 October 2018 at priority 2, and its table now lists 89 identifiers, every one of them credited to someone outside Adobe. The size has a single explanation. Netanel Ben-Simon and Yoav Alon of Check Point Software Technologies are credited on one acknowledgement line holding 35 identifiers, which is the output of the campaign they published as "50 Adobe CVEs in 50 days". They describe building a WinAFL harness against JP2KLib.dll, the library inside Reader that parses JPEG2000 images, and fuzzing that one component rather than the whole application. Their write-up lists 54 identifiers in total, so 35 of those 54 landed in this bulletin. The next largest credits are Lin Wang of Beihang University with 9 across two lines, seven reported directly and two through Trend Micro's Zero Day Initiative, and Ke Liu of Tencent Security Xuanwu Lab with 11. Fifteen of the 89 came in through the Zero Day Initiative in total.

Check Point says its campaign aimed at one image parser inside Reader, and Adobe's credit line is what ties 35 identifiers in this announcement to that campaign. If the record you are reading is one of those 35, that tells you where the researchers were looking and nothing about what Adobe changed. Each entry is its own defect with its own fix, and the other 54 identifiers here have other reporters entirely.

2018-10-01Adobe publishes APSB18-30 for Acrobat and Reader at priority 2
2018-11-26Adobe updates the acknowledgements section
2018-12-12Check Point publishes the write-up of the WinAFL campaign against Reader's JPEG2000 parser
2018-12-14Adobe adds CVE-2018-19722 to the bulletin
2019-02-05Adobe updates the acknowledgements section again

Adobe's table gives a bug class and an impact per entry and never names a component, so the bulletin cannot tell you whether a given record is an image parser crash or something unrelated. Only the credit line hints at it, and a credit is not a component. Check Point's write-up lists 54 identifiers while Adobe credits the pair with 35 here, so the remaining 19 belong to other announcements that this bulletin does not name.

Written from web.archive.org, research.checkpoint.com, helpx.adobe.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2018-12759no title heldOut-of-bounds write
CVE-2018-12769no title heldUse After Free
CVE-2018-12831no title heldUse After Free
CVE-2018-12832no title heldHeap Overflow
CVE-2018-12833no title heldHeap Overflow
CVE-2018-12834no title heldOut-of-bounds read
CVE-2018-12835no title heldType Confusion
CVE-2018-12836no title heldHeap Overflow
CVE-2018-12837no title heldHeap Overflow
CVE-2018-12838stackStack Overflow
CVE-2018-12839no title heldOut-of-bounds read
CVE-2018-12841doubleDouble Free
CVE-2018-12842no title heldInteger Overflow
CVE-2018-12843no title heldOut-of-bounds read
CVE-2018-12844no title heldOut-of-bounds read
CVE-2018-12845no title heldOut-of-bounds read
CVE-2018-12846no title heldHeap Overflow
CVE-2018-12847no title heldHeap Overflow
CVE-2018-12851no title heldHeap Overflow
CVE-2018-12852no title heldUse After Free
CVE-2018-12853no title heldBuffer Errors
CVE-2018-12855no title heldBuffer Errors
CVE-2018-12856no title heldOut-of-bounds read
CVE-2018-12857no title heldOut-of-bounds read
CVE-2018-12858no title heldType Confusion
CVE-2018-12859no title heldOut-of-bounds read
CVE-2018-12860no title heldOut-of-bounds write
CVE-2018-12861no title heldOut-of-bounds write
CVE-2018-12862no title heldOut-of-bounds write
CVE-2018-12863no title heldUse After Free
CVE-2018-12864no title heldOut-of-bounds write
CVE-2018-12865no title heldOut-of-bounds write
CVE-2018-12866no title heldOut-of-bounds read
CVE-2018-12867no title heldOut-of-bounds read
CVE-2018-12868no title heldOut-of-bounds write
CVE-2018-12869no title heldOut-of-bounds read
CVE-2018-12870no title heldOut-of-bounds read
CVE-2018-12871no title heldOut-of-bounds read
CVE-2018-12872no title heldOut-of-bounds read
CVE-2018-12873no title heldOut-of-bounds read
CVE-2018-12874no title heldOut-of-bounds read
CVE-2018-12875no title heldOut-of-bounds read
CVE-2018-12876no title heldType Confusion
CVE-2018-12877no title heldUse After Free
CVE-2018-12878no title heldOut-of-bounds read
CVE-2018-12879no title heldOut-of-bounds read
CVE-2018-12880no title heldOut-of-bounds read
CVE-2018-12881no title heldInteger Overflow
CVE-2018-15920no title heldUse After Free
CVE-2018-15922no title heldOut-of-bounds read
CVE-2018-15923no title heldOut-of-bounds read
CVE-2018-15924no title heldUse After Free
CVE-2018-15925no title heldOut-of-bounds read
CVE-2018-15926no title heldOut-of-bounds read
CVE-2018-15927no title heldOut-of-bounds read
CVE-2018-15928no title heldOut-of-bounds write
CVE-2018-15929no title heldOut-of-bounds write
CVE-2018-15930no title heldUntrusted pointer dereference
CVE-2018-15931no title heldUntrusted pointer dereference
CVE-2018-15932no title heldOut-of-bounds read
CVE-2018-15933no title heldOut-of-bounds write
CVE-2018-15934no title heldOut-of-bounds write
CVE-2018-15935no title heldOut-of-bounds write
CVE-2018-15936no title heldOut-of-bounds write
CVE-2018-15937no title heldUntrusted pointer dereference
CVE-2018-15938no title heldOut-of-bounds write
CVE-2018-15939no title heldOut-of-bounds write
CVE-2018-15940no title heldOut-of-bounds write
CVE-2018-15941no title heldOut-of-bounds write
CVE-2018-15942no title heldOut-of-bounds read
CVE-2018-15943no title heldOut-of-bounds read
CVE-2018-15944no title heldOut-of-bounds write
CVE-2018-15945no title heldOut-of-bounds write
CVE-2018-15946no title heldOut-of-bounds read
CVE-2018-15947no title heldOut-of-bounds read
CVE-2018-15948no title heldOut-of-bounds read
CVE-2018-15949no title heldOut-of-bounds read
CVE-2018-15950no title heldOut-of-bounds read
CVE-2018-15951no title heldBuffer Errors
CVE-2018-15952no title heldOut-of-bounds write
CVE-2018-15953no title heldOut-of-bounds read
CVE-2018-15954no title heldOut-of-bounds write
CVE-2018-15955no title heldOut-of-bounds write
CVE-2018-15956no title heldOut-of-bounds read
CVE-2018-15966security bypass privilege escalationSecurity Bypass
CVE-2018-15968no title heldOut-of-bounds read
CVE-2018-19722no title held

87 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.