9.3
CVE-2017-16387
- EPSS 8.68%
- Veröffentlicht 09.12.2017 06:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@adobe.com
- Teams Watchlist Login
- Unerledigt Login
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of the JPEG2000 codec. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Acrobat Dc SwEditioncontinuous Version >= - <= 17.012.20098
Adobe ≫ Acrobat Dc SwEditionclassic Version >= 15.0 <= 15.006.30355
Adobe ≫ Acrobat Reader Version <= 11.0.22
Adobe ≫ Acrobat Reader Version >= 17.0 <= 17.011.30066
Adobe ≫ Acrobat Reader Dc SwEditioncontinuous Version >= - <= 17.012.20098
Adobe ≫ Acrobat Reader Dc SwEditionclassic Version >= 15.0 <= 15.006.30355
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 8.68% | 0.921 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.