5

CVE-2014-8452

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Data is provided by the National Vulnerability Database (NVD)
AdobeAcrobat Reader Version10.0
AdobeAcrobat Reader Version10.0.1
AdobeAcrobat Reader Version10.0.2
AdobeAcrobat Reader Version10.0.3
AdobeAcrobat Reader Version10.1
AdobeAcrobat Reader Version10.1.1
AdobeAcrobat Reader Version10.1.2
AdobeAcrobat Reader Version10.1.3
AdobeAcrobat Reader Version10.1.4
AdobeAcrobat Reader Version10.1.5
AdobeAcrobat Reader Version10.1.6
AdobeAcrobat Reader Version10.1.7
AdobeAcrobat Reader Version10.1.8
AdobeAcrobat Reader Version10.1.9
AdobeAcrobat Reader Version10.1.10
AdobeAcrobat Reader Version10.1.11
AdobeAcrobat Reader Version10.1.12
AdobeAcrobat Reader Version11.0.0
AdobeAcrobat Reader Version11.0.01
AdobeAcrobat Reader Version11.0.02
AdobeAcrobat Reader Version11.0.03
AdobeAcrobat Reader Version11.0.04
AdobeAcrobat Reader Version11.0.05
AdobeAcrobat Reader Version11.0.06
AdobeAcrobat Reader Version11.0.07
AdobeAcrobat Reader Version11.0.08
AdobeAcrobat Reader Version11.0.09
AdobeAcrobat Version10.0
AdobeAcrobat Version10.0.1
AdobeAcrobat Version10.0.2
AdobeAcrobat Version10.0.3
AdobeAcrobat Version10.1
AdobeAcrobat Version10.1.1
AdobeAcrobat Version10.1.2
AdobeAcrobat Version10.1.3
AdobeAcrobat Version10.1.4
AdobeAcrobat Version10.1.5
AdobeAcrobat Version10.1.6
AdobeAcrobat Version10.1.7
AdobeAcrobat Version10.1.8
AdobeAcrobat Version10.1.9
AdobeAcrobat Version10.1.10
AdobeAcrobat Version10.1.11
AdobeAcrobat Version10.1.12
AdobeAcrobat Version11.0
AdobeAcrobat Version11.0.1
AdobeAcrobat Version11.0.2
AdobeAcrobat Version11.0.3
AdobeAcrobat Version11.0.4
AdobeAcrobat Version11.0.5
AdobeAcrobat Version11.0.6
AdobeAcrobat Version11.0.7
AdobeAcrobat Version11.0.8
AdobeAcrobat Version11.0.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 12.44% 0.937
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.