CVE-2013-3351: Buffer Overflow
Published Sep 11, 2013
·Updated
Multiple stack-based buffer overflows in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allow attackers to execute arbitrary code via unspecified vectors.
Affected Software
36 affected components
Adobe Acrobat Reader=10.0
Adobe Acrobat Reader=10.0.1
Adobe Acrobat Reader=10.0.2
Adobe Acrobat Reader=10.0.3
Adobe Acrobat Reader=10.1
Adobe Acrobat Reader=10.1.1
Adobe Acrobat Reader=10.1.2
Adobe Acrobat Reader=10.1.3
Adobe Acrobat Reader=10.1.4
Adobe Acrobat Reader=10.1.5
Adobe Acrobat Reader=10.1.6
Adobe Acrobat Reader=10.1.7
Apple iOS and macOS
Microsoft Windows
Adobe Acrobat=10.0
Adobe Acrobat=10.0
Adobe Acrobat=10.0.1
Adobe Acrobat=10.0.1
Adobe Acrobat=10.0.2
Adobe Acrobat=10.0.3
Adobe Acrobat=10.1
Adobe Acrobat=10.1.1
Adobe Acrobat=10.1.2
Adobe Acrobat=10.1.3
Adobe Acrobat=10.1.4
Adobe Acrobat=10.1.5
Adobe Acrobat=10.1.6
Adobe Acrobat=10.1.7
Adobe Acrobat=11.0
Adobe Acrobat=11.0.1
Adobe Acrobat=11.0.2
Adobe Acrobat=11.0.3
Adobe Acrobat Reader=11.0
Adobe Acrobat Reader=11.0.1
Adobe Acrobat Reader=11.0.2
Adobe Acrobat Reader=11.0.3
Remediation
Event History
Sep 11, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3351?
CVE-2013-3351 has a high severity rating due to its potential for attackers to execute arbitrary code.
2
How do I fix CVE-2013-3351?
To fix CVE-2013-3351, users should update Adobe Reader and Acrobat to version 10.1.8 or later, or 11.0.4 or later.
3
Which versions of Adobe Reader are affected by CVE-2013-3351?
CVE-2013-3351 affects Adobe Reader versions prior to 10.1.8 and 11.x prior to 11.0.4.
4
Can CVE-2013-3351 be exploited remotely?
Yes, CVE-2013-3351 can potentially be exploited remotely by an attacker through crafted PDF files.
5
What are the implications of CVE-2013-3351 for organizations?
Organizations using vulnerable versions of Adobe Reader and Acrobat face significant risks of unauthorized code execution, which can lead to data breaches.