CVE detail
CVE-2013-0641
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- Why do we need for Incident Response plan?Security Affairs
Due to the constant growth in the number of cyber attacks it is necessary to properly define the actions composing an incident response plan. FireEye firm published an interesting post on the need of incident response (IR) capabilities to reply numerous cyber attacks that daily hit almost any web service. Starting from the data proposed […]
newssecurityaffairs.comNov 26, 2013, 7:58 PM Attackers are taking advantage of public interest in security firm Mandiant’s recent report on state-sponsored hacking by China by using a fake copy of the report as bait for victims.
newswww.securityweek.comFeb 21, 2013, 5:04 PMAdobe on Wednesday issued patches to address recently disclosed security vulnerabilities in its Adobe Reader and Acrobat products that were found being actively exploited in the wild in targeted attacks.
newswww.securityweek.comFeb 20, 2013, 1:53 PMLast week, security researchers from FireEye identified a PDF zero-day that was being used in targeted attacks. Shortly after, Adobe confirmed the existence of two critical vulnerabilities in Adobe Reader and Acrobat XI for Windows and Macintosh that were being exploited in active attacks.
newswww.securityweek.comFeb 18, 2013, 11:22 AMAdobe Systems said it will release patches for two critical vulnerabilities disclosed last week that are actively being used by attackers. The company said on Saturday the patches will be released sometime this week. Both vulnerabilities can be exploited if a user can be tricked into opening a malicious PDF, which is usually sent to […]
newswww.csoonline.comFeb 17, 2013, 3:00 PM- Adobe offers mitigation for Reader 0-day attack, fix is yet to comeHelp Net Security
Adobe has confirmed FireEye researchers’ findings about new Adobe Reader and Acrobat zero-day vulnerabilities being exploited in the wild and has issued a security bulletin detailing the flaws and offering mitigation advice until a patch is released. The vulnerabilities (CVE-2013-0640, CVE-2013-0641) are present in Adobe Reader and Acrobat 11.0.01, 10.1.5, 9.5.3 and all their earlier versions for Windows and Macintosh, and allow attackers to compromise the systems of users who have been tricked into opening … More →
newswww.helpnetsecurity.comFeb 14, 2013, 9:13 AM After security researchers from FireEye said they identified a PDF zero-day that was being used in targeted attacks, Adobe late Wednesday confirmed the existence of two critical vulnerabilities in Adobe Reader and Acrobat XI for Windows and Macintosh that are being exploited in active attacks.
newswww.securityweek.comFeb 14, 2013, 2:53 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2013-0640CVSS 7.8 · High
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corrup…
- CVE-2015-5119CVSS 9.8 · Critical
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows…
- CVE-2014-0502CVSS 8.8 · High
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR…
- CVE-2014-0497CVSS 9.8 · Critical
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote att…
- CVE-2013-0648CVSS 8.8 · High
Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and be…
KEV listed3 mentions - CVE-2013-0643CVSS 8.8 · High
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, do…