peter bassill · operator
$ cve CVE-2015-3073 JSON

CVE-2015-3073 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 25.5% (pctl 98)

Patch early

A public exploit exists.

Description

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS25.47% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploityes
Published2015-05-13
Last modified2026-06-17

Affected (4)

VendorProduct
adobeacrobat
adobeacrobat reader
applemac os x
microsoftwindows

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD