peter bassill · operator
$ cve CVE-2016-6949 JSON

CVE-2016-6949

9.8
CRITICAL · CVSS 3.0 · EPSS 7.2% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1089, CVE-2016-1091, CVE-2016-6944, CVE-2016-6945, CVE-2016-6946, CVE-2016-6952, CVE-2016-6953, CVE-2016-6961, CVE-2016-6962, CVE-2016-6963, CVE-2016-6964, CVE-2016-6965, CVE-2016-6967, CVE-2016-6968, CVE-2016-6969, CVE-2016-6971, CVE-2016-6979, CVE-2016-6988, and CVE-2016-6993.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.19% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploitnone known
Published2016-10-13
Last modified2026-06-17

Affected (6)

VendorProduct
adobeacrobat
adobeacrobat dc
adobeacrobat reader dc
adobereader
applemac os x
microsoftwindows

References

→ the Explorer  ·  watch your stack  ·  NVD