The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Apsb11 03 | — | — | Feb 13, 2011 | Feb 8, 2011 |
| Adobe Reader Apsb10 28 | — | — | Apr 12, 2012 | Nov 7, 2010 |
| Adobe Reader Apsb11 03 | — | — | Apr 12, 2012 | Nov 7, 2010 |
| Gentoo Linux | — | Upgrade app-text/acroread. | Oct 30, 2017 | Nov 7, 2010 |
| Suse | — | Upgrade acroread-fonts-zh_TWUpgrade acroread-fonts-zh_CNUpgrade acroread-fonts-koUpgrade acroread-cmapsUpgrade acroreadUpgrade acroread_jaUpgrade acroread-fonts-ja | Feb 17, 2015 | Nov 7, 2010 |
| Ubuntu | — | Upgrade acroreadUpgrade adobereader-deu | Nov 19, 2024 | Nov 7, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub