HIGH🇵🇱 Wersja polska

CVE-2015-5099

CVSS 10.0v2.0pub. 2015-07-15upd. 2026-05-06

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-4448, CVE-2015-5095, CVE-2015-5101, CVE-2015-5111, CVE-2015-5113, and CVE-2015-5114.

CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Adobe Acrobat

    APP
    Adobe
    10.0 – 10.1.1411.0.0 – 11.0.11
  • Adobe Acrobat DC

    APP
    Adobe
    15.006.30033 – 15.006.30060 (excl.)15.007.20033 – 15.008.20082 (excl.)
  • Adobe Acrobat Reader

    APP
    Adobe
    10.0 – 10.1.1411.0.0 – 11.0.11
  • Adobe Acrobat Reader Dc

    APP
    Adobe
    15.006.30033 – 15.006.30060 (excl.)15.007.20033 – 15.008.20082 (excl.)
  • Apple macOS

    OS
    Apple
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP