Description
Adobe Reader and Acrobat 11.x before 11.0.05 on Windows allow remote attackers to execute arbitrary JavaScript code in a javascript: URL via a crafted PDF document.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19053
Vendor Advisory x_refsource_confirm
http://www.adobe.com/support/security/bulletins/apsb13-25.html
Scores
EPSS
0.0364
EPSS Percentile
88.2%
Details
CWE
CWE-94
Status
published
Products (10)
adobe/acrobat
11.0
adobe/acrobat
11.0.1
adobe/acrobat
11.0.2
adobe/acrobat
11.0.3
adobe/acrobat
11.0.4
adobe/acrobat_reader
11.0
adobe/acrobat_reader
11.0.1
adobe/acrobat_reader
11.0.2
adobe/acrobat_reader
11.0.3
adobe/acrobat_reader
11.0.4
Published
Oct 09, 2013
Tracked Since
Feb 18, 2026