Kaspersky ID:
KLA10004
Дата обнаружения:
13/05/2014
Обновлено:
18/06/2020

Описание

Multiple serious vulnerabilities have been found in Adobe Reader & Adobe Acrobat versions X and XI. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass a sandbox protection, cause a denial of service or obtain sensitive information.

Below is a complete list of vulnerabilities

  1. Vectors related to unknown can be exploited to bypass a sandbox protection mechanism, execute arbitrary code or cause a denial of service via heap-based buffer overflow, use-after-free and double free.

  2. Vectors related to JavaScript API can be exploited to obtain sensitive information via a specially designed PDF

  3. Vectors related to unknown API calls can be exploited to execute arbitrary code via unmapped memory access.

Первичный источник обнаружения

Эксплуатация

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Связанные продукты

Список CVE

  • CVE-2014-0511
    critical
  • CVE-2014-0521
    warning
  • CVE-2014-0526
    critical
  • CVE-2014-0525
    critical
  • CVE-2014-0529
    critical
  • CVE-2014-0527
    critical
  • CVE-2014-0528
    critical
  • CVE-2014-0522
    critical
  • CVE-2014-0512
    critical
  • CVE-2014-0524
    critical
  • CVE-2014-0523
    critical

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Confirm changes?
Your message has been sent successfully.