Vulnerability Summary Report of May, 2019
Total Page:16
File Type:pdf, Size:1020Kb
1 SB19-154 VULNERABILITY SUMMARY FOR MAY 2019 2 SB19-154 Vulnerability Summary for May 2019 Cybernetic GI Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team, is sponsored by The NVD. For modified or updated entries, please visit the NVD, which contains historical vulnerability information. The vulnerabilities are based on the CVE vulnerability naming standard and determined by the Common Vulnerability Scoring System (CVSS) standard. They are organized according to severity, by the division of high, medium and low severities correspond to the following scores: High -Vulnerabilities will be labeled High severity if they have a CVSS base score of 10.0 - 7.0. Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of - 4.0 6.9 Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 3.9 - 0.0 Entries may include additional information provided by organizations and efforts sponsored by Cybernetic GI. This data may include identifying information, values, definitions, and related links. The patch information is provided to users when available. Please note that some of the information in the bulletin is compiled from external, open source reports and is not a direct result of Cybernetic GI analysis. The NCCIC Weekly Vulnerability Summary Bulletin is created using information from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD). In some cases, the vulnerabilities in the bulletin may not yet have assigned CVSS scores. Please visit NVD for updated vulnerability entries, which include CVSS scores once they are available. Source references taken from US-CERT. 3 High Vulnerabilities Primary Description Published CVSS Source & Vendor -- Product Score Patch Info adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7018 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7019 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7020 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have a buffer errors vulnerability. Success- ful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7025 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7026 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7029 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7031 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7037 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7039 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7040 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 9.3 CVE-2019-7042 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 9.3 CVE-2019-7043 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 9.3 CVE-2019-7043 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 9.3 CVE-2019-7044 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7046 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 9.3 CVE-2019-7048 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7050 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution. 4 adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7051 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an untrusted pointer dereference vul- nerability. Successful exploitation could lead to arbitrary code dexecution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7052 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7054 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an untrusted pointer dereference vul- nerability. Successful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7060 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7062 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7066 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an untrusted pointer dereference vul- nerability. Successful exploitation could lead to arbitrary code execution . adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 10.0 CVE-2019-7068 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have an use after free vulnerability. Suc- cessful exploitation could lead to arbitrary code execution. adobe -- acrobat Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019-05-24 9.3 CVE-2019-7069 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and CONFIRM 2015.006.30464 and earlier have a type confusion vulnerability.