CVE-2016-6939
published 2016-10-13CVE-2016-6939: Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat…
PriorityP353critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
8.50%
94.5th percentile
Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-6994.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 11.0.17 | — |
| adobe | acrobat_dc | <= 15.006.30201 | — |
| adobe | acrobat_dc | <= 15.017.20053 | — |
| adobe | acrobat_reader_dc | <= 15.006.30201 | — |
| adobe | acrobat_reader_dc | <= 15.017.20053 | — |
| adobe | reader | <= 11.0.17 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-89v9-9pwr-72v2: Heap-based buffer overflow in Adobe Reader and Acrobat before 11
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-6994 [CRITICAL] CWE-119 GHSA-89v9-9pwr-72v2: Heap-based buffer overflow in Adobe Reader and Acrobat before 11
Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-6939.
GHSA
GHSA-fhww-mg2m-x83m: Heap-based buffer overflow in Adobe Reader and Acrobat before 11
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-6939 [CRITICAL] CWE-119 GHSA-fhww-mg2m-x83m: Heap-based buffer overflow in Adobe Reader and Acrobat before 11
Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-6994.
No detection rules found.
No public exploits indexed.
Fortinet
Fortinet Researchers Discover Two Critical Vulnerabilities in Adobe Acrobat and Reader
blogs_fortinet·2016-10-21·CVSS 9.8
CVE-2016-6939 [CRITICAL] Fortinet Researchers Discover Two Critical Vulnerabilities in Adobe Acrobat and Reader
FORTIGUARD LABS THREAT RESEARCH
Fortinet Researchers Discover Two Critical Vulnerabilities in Adobe Acrobat and Reader
By Kai Lu and Kushal Shah | October 21, 2016
Fortinet researchers recently discovered two critical zero-day vulnerabilities in Adobe Acrobat and Reader. They are identified as CVE-2016-6939 and CVE-2016-6948. Adobe released a patch to fix these vulnerabilities on October 6, 2016.
CVE-2016-6939
This vulnerability was discovered by Kai Lu.
CVE-2016-6939 is a heap overflow vulnerability. The vulnerability is caused by a crafted PDF file which causes an out of bounds memory access due to an improper bounds check when manipulating an array pointer. The specific vulnerability exists in the MakeAccessible plugin due to missing length checks.
Attackers can exploit the vulnerab
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 10-11-2016
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 10-11-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2016-10-13
Published