CVE detail
CVE-2013-0640
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- A Week in Security (May 4 – 10)Malwarebytes Labs
Here’s a review of last week’s posts on Malwarebytes Unpacked: Top news stories: Stay secure, everyone! The Malwarebytes Labs Team
newswww.malwarebytes.comMay 11, 2014, 5:00 PM - F-Secure has discovered MiniDuke malware samples in the wildSecurity Affairs
Security Experts at F-Secure discovered a collection of pdf documents, that had references to Ukraine, containing MiniDuke malware samples. MiniDuke is the name of a sophisticated cyber espionage campaign discovered more than one year ago by experts at Kaspersky Lab and Hungary’s Laboratory of Cryptography and System Security (CrySyS). The malicious code was used by unknown hackers to […]
newssecurityaffairs.comApr 3, 2014, 6:26 AM - Why do we need for Incident Response plan?Security Affairs
Due to the constant growth in the number of cyber attacks it is necessary to properly define the actions composing an incident response plan. FireEye firm published an interesting post on the need of incident response (IR) capabilities to reply numerous cyber attacks that daily hit almost any web service. Starting from the data proposed […]
newssecurityaffairs.comNov 26, 2013, 7:58 PM Researchers at AlienVault shed some light on the evolution of the Sykipot malware attacks. The Sykipot attacks have exploited a number of zero-days during the past few years, including vulnerabilities affecting Adobe Reader, Adobe Flash Player and Microsoft Internet Explorer.
newswww.securityweek.comMar 21, 2013, 6:54 PMAttackers are using a new Adobe Reader exploit to target Tibetan and Uyghur activists to drop an advanced piece of malware, according to researchers from AlienVault and Kaspersky Lab.
newswww.securityweek.comMar 14, 2013, 9:29 PMAdobe on Wednesday issued patches to address recently disclosed security vulnerabilities in its Adobe Reader and Acrobat products that were found being actively exploited in the wild in targeted attacks.
newswww.securityweek.comFeb 20, 2013, 1:53 PMLast week, security researchers from FireEye identified a PDF zero-day that was being used in targeted attacks. Shortly after, Adobe confirmed the existence of two critical vulnerabilities in Adobe Reader and Acrobat XI for Windows and Macintosh that were being exploited in active attacks.
newswww.securityweek.comFeb 18, 2013, 11:22 AMAdobe Systems said it will release patches for two critical vulnerabilities disclosed last week that are actively being used by attackers. The company said on Saturday the patches will be released sometime this week. Both vulnerabilities can be exploited if a user can be tricked into opening a malicious PDF, which is usually sent to […]
newswww.csoonline.comFeb 17, 2013, 3:00 PM- Adobe offers mitigation for Reader 0-day attack, fix is yet to comeHelp Net Security
Adobe has confirmed FireEye researchers’ findings about new Adobe Reader and Acrobat zero-day vulnerabilities being exploited in the wild and has issued a security bulletin detailing the flaws and offering mitigation advice until a patch is released. The vulnerabilities (CVE-2013-0640, CVE-2013-0641) are present in Adobe Reader and Acrobat 11.0.01, 10.1.5, 9.5.3 and all their earlier versions for Windows and Macintosh, and allow attackers to compromise the systems of users who have been tricked into opening … More →
newswww.helpnetsecurity.comFeb 14, 2013, 9:13 AM After security researchers from FireEye said they identified a PDF zero-day that was being used in targeted attacks, Adobe late Wednesday confirmed the existence of two critical vulnerabilities in Adobe Reader and Acrobat XI for Windows and Macintosh that are being exploited in active attacks.
newswww.securityweek.comFeb 14, 2013, 2:53 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2013-0641CVSS 7.8 · High
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF docum…
- CVE-2015-3113CVSS 9.8 · Critical
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attac…
- CVE-2015-3043CVSS 9.8 · Critical
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cau…
- CVE-2012-2035CVSS 9.3 · Critical
Stack-based buffer overflow in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux…
- CVE-2015-5119CVSS 9.8 · Critical
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows…
- CVE-2014-0502CVSS 8.8 · High
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR…