CVE-2014-0514

Adobe Reader < 11.1.3 - Access Control

Title source: rule

Description

The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-6636.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalarm
https://www.exploit-db.com/exploits/33791
exploitdb WORKING POC VERIFIED
by Yorick Koster · textlocalandroid
https://www.exploit-db.com/exploits/32884
metasploit WORKING POC GOOD
by Yorick Koster, joev · rubypocandroid
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/android/fileformat/adobe_reader_pdf_js_interface.rb

Scores

EPSS 0.9029
EPSS Percentile 99.6%

Details

CWE
CWE-264
Status published
Products (2)
adobe/adobe_reader 11.1.0
adobe/adobe_reader < 11.1.3
Published Apr 15, 2014
Tracked Since Feb 18, 2026