CVE-2013-0641
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Reader Buffer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 32% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-120
מוצרים מושפעים
adobe: acrobat; adobe: acrobat reader; apple: mac os x; microsoft: windows; linux: linux kernel; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux server; redhat: enterprise linux server aus; redhat: enterprise linux workstation; opensuse: opensuse; suse: linux enterprise desktop
קישורים
- http://blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-re… Broken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa13-02.html Vendor Advisory
- http://blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-re… Broken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa13-02.html Vendor Advisory
- http://blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.html Broken Link
- http://blogs.mcafee.com/mcafee-labs/digging-into-the-sandbox-escape-technique-… Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00021.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00023.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00024.html Mailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0551.html Third Party Advisory