CVE-2016-1043
9.8
CRITICAL · CVSS 3.0 · EPSS 6.6% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Integer overflow in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.57% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-05-11 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat dc |
| adobe | acrobat reader dc |
| adobe | reader |
| apple | mac os x |
| microsoft | windows |
References
- http://www.securityfocus.com/bid/90516
- http://www.securitytracker.com/id/1035828
- http://www.zerodayinitiative.com/advisories/ZDI-16-286
- https://helpx.adobe.com/security/products/acrobat/apsb16-14.html
- http://www.securityfocus.com/bid/90516
- http://www.securitytracker.com/id/1035828
- http://www.zerodayinitiative.com/advisories/ZDI-16-286
- https://helpx.adobe.com/security/products/acrobat/apsb16-14.html
→ the Explorer · watch your stack · NVD