9.3

CVE-2017-16384

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer over-read in the exif processing module for a PNG file (during XPS conversion). Invalid input leads to a computation where pointer arithmetic results in a location outside valid memory locations belonging to the buffer. An attack can be used to obtain sensitive information, such as object heap addresses, etc.

Data is provided by the National Vulnerability Database (NVD)
AdobeAcrobat Version <= 11.0.22
AdobeAcrobat Version >= 17.0 <= 17.011.30066
AdobeAcrobat Dc SwEditioncontinuous Version >= - <= 17.012.20098
AdobeAcrobat Dc SwEditionclassic Version >= 15.0 <= 15.006.30355
AdobeAcrobat Reader Version <= 11.0.22
AdobeAcrobat Reader Version >= 17.0 <= 17.011.30066
AdobeAcrobat Reader Dc SwEditioncontinuous Version >= - <= 17.012.20098
AdobeAcrobat Reader Dc SwEditionclassic Version >= 15.0 <= 15.006.30355
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 17.92% 0.949
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.