6.5

CVE-2018-4883

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs because of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion engine that handles Enhanced Metafile Format (EMF). A successful attack can lead to sensitive data exposure.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeAcrobat Version > 17.0 <= 17.011.30070
AdobeAcrobat Dc SwEditioncontinuous Version >= - <= 18.009.20050
AdobeAcrobat Dc SwEditionclassic Version >= 15.0 <= 15.006.30394
AdobeAcrobat Reader Version >= 17.0 <= 17.011.30070
AdobeAcrobat Reader Dc SwEditioncontinuous Version >= - <= 18.009.20050
AdobeAcrobat Reader Dc SwEditionclassic Version >= 15.0 <= 15.006.30394
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.88% 0.825
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.