CVE-2013-2724Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe Acrobat

Severity
10.0CRITICALNVD
EPSS
32.7%
top 3.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 17

Description

Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDadobe/acrobat_reader38 versions+37
NVDadobe/acrobat38 versions+37

Patches

🔴Vulnerability Details

1
GHSA
GHSA-f3m8-85h8-4834: Stack-based buffer overflow in Adobe Reader and Acrobat 92022-05-17

📋Vendor Advisories

1
Red Hat
acroread: multiple code execution flaws (APSB13-15)2013-05-14

💬Community

1
Bugzilla
acroread: multiple code execution flaws (APSB13-15)2013-05-14
CVE-2013-2724 — Adobe Acrobat vulnerability | cvebase