CVE-2013-0640
adobe acrobat, adobe acrobat reader, opensuse
Published 14 Feb 2013 · updated 16 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 24 Mar 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.
References
- blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.html · Broken Link
- blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-report.html · Broken Link
- lists.opensuse.org/opensuse-security-announce/2013-02/msg00021.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2013-02/msg00023.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2013-02/msg00024.html · Mailing List, Third Party Advisory
- rhn.redhat.com/errata/RHSA-2013-0551.html · Third Party Advisory
- security.gentoo.org/glsa/glsa-201308-03.xml · Third Party Advisory
- www.adobe.com/support/security/advisories/apsa13-02.html · Vendor Advisory
- www.adobe.com/support/security/bulletins/apsb13-07.html · Broken Link
- www.kb.cert.org/vuls/id/422807 · Third Party Advisory, US Government Resource
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16406 · Broken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0640 · US Government Resource