CVE-2016-6937
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, CVE-2016-4254, CVE-2016-4265, CVE-2016-4266, CVE-2016-4267, CVE-2016-4268, CVE-2016-4269, and CVE-2016-4270.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.62% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-09-17 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat dc |
| adobe | acrobat reader dc |
| adobe | reader |
| apple | mac os x |
| microsoft | windows |
References
- http://www.securityfocus.com/bid/93014
- http://www.securitytracker.com/id/1036986
- http://www.securitytracker.com/id/1037574
- http://www.zerodayinitiative.com/advisories/ZDI-16-574
- https://helpx.adobe.com/security/products/acrobat/apsb16-26.html
- http://www.securityfocus.com/bid/93014
- http://www.securitytracker.com/id/1036986
- http://www.securitytracker.com/id/1037574
- http://www.zerodayinitiative.com/advisories/ZDI-16-574
- https://helpx.adobe.com/security/products/acrobat/apsb16-26.html
→ the Explorer · watch your stack · NVD