acroread: multiple code execution flaws (APSB13-15)
Published Aug 30, 2013 ·Due Mar 24, 2022
9.8
CRITICALCVSS 3.1
EPSS 78.91%
Description
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.
Affected products
No data.
- ≥ 9.0 · < 9.5.5
- ≥ 10.0 · < 10.1.7
- ≥ 11.0 · < 11.0.03
- ≥ 9.0 · < 9.5.5
- ≥ 10.0 · < 10.1.7
- ≥ 11.0 · < 11.0.03
No data.
Supplementary for Red Hat Enterprise Linux 5
acroread-0:9.5.5-1.el5_9
Fixed · RHSA-2013:0826
Supplementary for Red Hat Enterprise Linux 6
acroread-0:9.5.5-1.el6_4
Fixed · RHSA-2013:0826
| Product | Package | State | Advisory |
|---|---|---|---|
| Supplementary for Red Hat Enterprise Linux 5 | acroread-0:9.5.5-1.el5_9 | Fixed | RHSA-2013:0826 |
| Supplementary for Red Hat Enterprise Linux 6 | acroread-0:9.5.5-1.el6_4 | Fixed | RHSA-2013:0826 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (CISA ADP) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
Mar 3, 2022
Patch Due
Mar 24, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Nov 21, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 78.91% (0.78913) | 99.59th | v5 (v2026.06.15) |
| Jun 15, 2026 | 78.44% (0.78437) | 99.53th | v5 (v2026.06.15) |
| May 15, 2025 | 89.44% (0.89436) | 99.51th | v4 (v2025.03.14) |
| Mar 17, 2025 | 88.09% (0.88092) | 99.46th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.98% (0.96984) | 99.79th | v3 (v2023.03.01) |
| Jul 20, 2024 | 97.27% (0.97270) | 99.87th | v3 (v2023.03.01) |
| May 17, 2024 | 97.20% (0.97198) | 99.82th | v3 (v2023.03.01) |
| Mar 17, 2024 | 97.27% (0.97265) | 99.83th | v3 (v2023.03.01) |
| Jan 23, 2024 | 97.31% (0.97308) | 99.86th | v3 (v2023.03.01) |
| Dec 4, 2023 | 97.38% (0.97383) | 99.90th | v3 (v2023.03.01) |
| Aug 29, 2023 | 97.31% (0.97311) | 99.80th | v3 (v2023.03.01) |
| Jul 13, 2023 | 97.33% (0.97333) | 99.80th | v3 (v2023.03.01) |
| May 27, 2023 | 97.40% (0.97396) | 99.86th | v3 (v2023.03.01) |
| Apr 12, 2023 | 97.22% (0.97217) | 99.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.13% (0.97129) | 99.60th | v3 (v2023.03.01) |
| Mar 6, 2023 | 94.32% (0.94318) | 99.95th | v2 (v2022.01.01) |
| Feb 11, 2022 | 94.32% (0.94318) | 99.94th | v2 (v2022.01.01) |
| Feb 4, 2022 | 94.90% (0.94896) | 99.96th | v2 (v2022.01.01) |
References (9)
- http://www.adobe.com/support/security/bulletins/apsb13-15.html x_refsource_CONFIRMBroken LinkVendor Advisory
- https://access.redhat.com/security/cve/CVE-2013-3346 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=962931 Issue Tracking
- https://github.com/cisagov/vulnrichment/issues/199 issue-trackingIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-3346
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19054 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3346 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2013-3346
| Link | Providers | Tags |
|---|---|---|
| http://www.adobe.com/support/security/bulletins/apsb13-15.html | x_refsource_CONFIRMBroken LinkVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2013-3346 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=962931 | Issue Tracking | |
| https://github.com/cisagov/vulnrichment/issues/199 | issue-trackingIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-3346 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19054 | vdb-entrysignaturex_refsource_OVALBroken Link | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3346 | government-resourceUS Government Resource | |
| https://www.cve.org/CVERecord?id=CVE-2013-3346 |
Change history (0)
No recorded changes yet.