CVE-2013-0603Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe Acrobat

Severity
10.0CRITICALNVD
EPSS
12.6%
top 6.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 17

Description

Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0604.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDadobe/acrobat_reader32 versions+31
NVDadobe/acrobat32 versions+31

Patches

🔴Vulnerability Details

2
GHSA
GHSA-282w-5q6m-5xx6: Heap-based buffer overflow in Adobe Reader and Acrobat 92022-05-17
GHSA
GHSA-57j5-p934-rxcj: Heap-based buffer overflow in Adobe Reader and Acrobat 92022-05-17

📋Vendor Advisories

2
Red Hat
acroread: multiple code execution flaws (APSB13-02)2013-01-08
Red Hat
acroread: multiple code execution flaws (APSB13-02)2013-01-08

💬Community

1
Bugzilla
acroread: multiple code execution flaws (APSB13-02)2013-01-09
CVE-2013-0603 — Adobe Acrobat vulnerability | cvebase