vciy

Adobe Acrobat and Reader: 86 records in one advisory

86 records announced together, published between 2019-01-18 and 2019-01-28, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb18-41.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.

Most commonly mapped weakness across the batch: Out-of-bounds read.

What this page does not cover

Every record citing this advisory is on this page.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Adobe's December 2018 Acrobat release, and the 86 records that followed it five weeks later

SecurityWeek reported that Adobe's December 2018 Acrobat and Reader update closed 87 vulnerabilities across the Continuous and Classic 2015 tracks and Acrobat 2017. It lists the organisations Adobe credited: Tencent, Source Incite, NSFocus, Beihang University, Trend Micro, the Chinese Academy of Sciences, Baidu, Qihoo 360, Ruhr University Bochum, Cisco Talos, Zero Day Initiative, Palo Alto Networks, Knownsec 404 and independent researchers. That is more than a dozen separate teams whose work happened to be ready for the same release. SecurityWeek also reports Adobe saying it had no indication that any of them had been exploited. The records themselves did not appear when the update did. Our index holds 86 records naming this bulletin, published between 18 January and 28 January 2019, five weeks after the update and spread across ten days.

These are separate faults in one document reader, found by teams competing against each other and by paid reporting programmes, and collected into one scheduled release. Installing the update is one action, but each record stands on its own and none of them describes the others.

2018-12-11Adobe publishes the bulletin, which SecurityWeek reports as closing 87 vulnerabilities in Acrobat and Reader
2019-01-18The first records naming this bulletin reach the CVE list, five weeks after the update

SecurityWeek lists the organisations Adobe credited but does not say which identifier belongs to which organisation, and Adobe's own acknowledgements table is not readable to us, so no record in this group can be matched to its reporter. There is also a count that does not line up: the release is reported as 87 vulnerabilities and we hold 86 records naming it, and no source we can read accounts for the missing one.

Written from securityweek.com, tenable.com, helpx.adobe.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2018-12830no title held
CVE-2018-15984no title held
CVE-2018-15985no title held
CVE-2018-15986no title held
CVE-2018-15987no title held
CVE-2018-15988no title held
CVE-2018-15989no title held
CVE-2018-15990no title held
CVE-2018-15991no title held
CVE-2018-15992no title held
CVE-2018-15993no title held
CVE-2018-15994no title held
CVE-2018-15995no title held
CVE-2018-15996no title held
CVE-2018-15997no title held
CVE-2018-15998no title held
CVE-2018-15999no title held
CVE-2018-16000no title held
CVE-2018-16001no title held
CVE-2018-16002no title held
CVE-2018-16003no title held
CVE-2018-16004no title held
CVE-2018-16005no title held
CVE-2018-16006no title held
CVE-2018-16007no title held
CVE-2018-16008no title held
CVE-2018-16009no title held
CVE-2018-16010no title held
CVE-2018-16012no title held
CVE-2018-16013no title held
CVE-2018-16014no title held
CVE-2018-16015no title held
CVE-2018-16016no title held
CVE-2018-16017no title held
CVE-2018-16019no title held
CVE-2018-16020no title held
CVE-2018-16021no title held
CVE-2018-16022no title held
CVE-2018-16023no title held
CVE-2018-16024no title held
CVE-2018-16025no title held
CVE-2018-16026no title held
CVE-2018-16027no title held
CVE-2018-16028no title held
CVE-2018-16029no title held
CVE-2018-16030no title held
CVE-2018-16031no title held
CVE-2018-16032no title held
CVE-2018-16033no title held
CVE-2018-16034no title held
CVE-2018-16035no title held
CVE-2018-16036no title held
CVE-2018-16037no title held
CVE-2018-16038no title held
CVE-2018-16039no title held
CVE-2018-16040no title held
CVE-2018-16041no title held
CVE-2018-16042no title held
CVE-2018-16043no title held
CVE-2018-16044no title held
CVE-2018-16045no title held
CVE-2018-16046no title held
CVE-2018-16047no title held
CVE-2018-19698no title held
CVE-2018-19699no title held
CVE-2018-19700no title held
CVE-2018-19701no title held
CVE-2018-19702no title held
CVE-2018-19703no title held
CVE-2018-19704no title held
CVE-2018-19705no title held
CVE-2018-19706no title held
CVE-2018-19707no title held
CVE-2018-19708no title held
CVE-2018-19709no title held
CVE-2018-19710no title held
CVE-2018-19711no title held
CVE-2018-19712no title held
CVE-2018-19713no title held
CVE-2018-19714no title held
CVE-2018-19715no title held
CVE-2018-19716no title held
CVE-2018-19717no title held
CVE-2018-19719no title held
CVE-2018-19720no title held
CVE-2018-19728no title heldOut-of-bounds read

86 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.