Skip to main content

CVE detail

CVE-2013-0640

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.

CVSS 7.8 · HighBuzz score 60.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 60.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
24.0
10 evidence mentions in the snapshot
Diversity score
11.0
5 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
10 source links · newest first
  • A Week in Security (May 4 – 10)Malwarebytes Labs

    Here’s a review of last week’s posts on Malwarebytes Unpacked: Top news stories: Stay secure, everyone! The Malwarebytes Labs Team

    newswww.malwarebytes.comMay 11, 2014, 5:00 PM
  • Security Experts at F-Secure discovered a collection of pdf documents, that had references to Ukraine, containing MiniDuke malware samples. MiniDuke is the name of a sophisticated cyber espionage campaign discovered more than one year ago by experts at Kaspersky Lab and Hungary’s Laboratory of Cryptography and System Security (CrySyS). The malicious code was used by unknown hackers to […]

    newssecurityaffairs.comApr 3, 2014, 6:26 AM
  • Why do we need for Incident Response plan?Security Affairs

    Due to the constant growth in the number of cyber attacks it is necessary to properly define the actions composing an incident response plan. FireEye firm published an interesting post on the need of incident response (IR) capabilities to reply numerous cyber attacks that daily hit almost any web service. Starting from the data proposed […]

    newssecurityaffairs.comNov 26, 2013, 7:58 PM
  • Researchers at AlienVault shed some light on the evolution of the Sykipot malware attacks. The Sykipot attacks have exploited a number of zero-days during the past few years, including vulnerabilities affecting Adobe Reader, Adobe Flash Player and Microsoft Internet Explorer.

    newswww.securityweek.comMar 21, 2013, 6:54 PM
  • Attackers are using a new Adobe Reader exploit to target Tibetan and Uyghur activists to drop an advanced piece of malware, according to researchers from AlienVault and Kaspersky Lab.

    newswww.securityweek.comMar 14, 2013, 9:29 PM
  • Adobe on Wednesday issued patches to address recently disclosed security vulnerabilities in its Adobe Reader and Acrobat products that were found being actively exploited in the wild in targeted attacks.

    newswww.securityweek.comFeb 20, 2013, 1:53 PM
  • Last week, security researchers from FireEye identified a PDF zero-day that was being used in targeted attacks. Shortly after, Adobe confirmed the existence of two critical vulnerabilities in Adobe Reader and Acrobat XI for Windows and Macintosh that were being exploited in active attacks.

    newswww.securityweek.comFeb 18, 2013, 11:22 AM
  • Adobe Systems said it will release patches for two critical vulnerabilities disclosed last week that are actively being used by attackers. The company said on Saturday the patches will be released sometime this week. Both vulnerabilities can be exploited if a user can be tricked into opening a malicious PDF, which is usually sent to […]

    newswww.csoonline.comFeb 17, 2013, 3:00 PM
  • Adobe has confirmed FireEye researchers’ findings about new Adobe Reader and Acrobat zero-day vulnerabilities being exploited in the wild and has issued a security bulletin detailing the flaws and offering mitigation advice until a patch is released. The vulnerabilities (CVE-2013-0640, CVE-2013-0641) are present in Adobe Reader and Acrobat 11.0.01, 10.1.5, 9.5.3 and all their earlier versions for Windows and Macintosh, and allow attackers to compromise the systems of users who have been tricked into opening … More →

    newswww.helpnetsecurity.comFeb 14, 2013, 9:13 AM
  • After security researchers from FireEye said they identified a PDF zero-day that was being used in targeted attacks, Adobe late Wednesday confirmed the existence of two critical vulnerabilities in Adobe Reader and Acrobat XI for Windows and Macintosh that are being exploited in active attacks.

    newswww.securityweek.comFeb 14, 2013, 2:53 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence