peter bassill · operator
$ cve CVE-2013-2729 JSON

CVE-2013-2729 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 66.6% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-18.

Description

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS66.56% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-190
On CISA KEVyes — remediate by 2022-04-18
Public exploityes
Published2013-05-16
Last modified2026-06-16

CISA KEV

NameAdobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability
Added2022-03-28
Due2022-04-18
Vendor / productAdobe / Reader and Acrobat
Ransomware usenone reported

Affected (8)

VendorProduct
adobeacrobat
adobeacrobat reader
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux workstation
suselinux enterprise desktop

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD