9.3
CVE-2013-0640
- EPSS 86.98%
- Veröffentlicht 14.02.2013 01:55:02
- Zuletzt bearbeitet 21.04.2026 21:01:36
- Erkennungen
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Acrobat Reader Version >= 10.0 < 10.1.6
Adobe ≫ Acrobat Reader Version >= 11.0 < 11.0.02
Suse ≫ Linux Enterprise Desktop Version 10 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Desktop Version 11 Update sp2
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 5.9
Redhat ≫ Enterprise Linux Eus Version 6.4
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Aus Version 5.9
Redhat ≫ Enterprise Linux Server Aus Version 6.4
Redhat ≫ Enterprise Linux Workstation Version 6.0
Adobe ≫ Acrobat Reader Version >= 9.0 < 9.5.4
03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Adobe Reader and Acrobat Memory Corruption Vulnerability
SchwachstelleAn memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 86.98% | 0.997 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
http://security.gentoo.org/glsa/glsa-201308-03.xml
http://blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.html
http://blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-report.html
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00023.html
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00024.html
http://rhn.redhat.com/errata/RHSA-2013-0551.html
http://www.adobe.com/support/security/advisories/apsa13-02.html
http://www.adobe.com/support/security/bulletins/apsb13-07.html
http://www.kb.cert.org/vuls/id/422807
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16406
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0640