← All CVEs

CVE-2010-4091

high · 9.3

The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these details are obtained from third party information.

9.3
CVSS
18.5%
EPSS (exploit prob.)
97th
EPSS percentile
2010-11-07
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
adobeacrobat_reader8.0
adobeacrobat_reader8.1
adobeacrobat_reader8.1.1
adobeacrobat_reader8.1.2
adobeacrobat_reader8.1.4
adobeacrobat_reader8.1.5
adobeacrobat_reader8.1.6
adobeacrobat_reader8.1.7
adobeacrobat_reader8.2
adobeacrobat_reader8.2.1
adobeacrobat_reader8.2.2
adobeacrobat_reader8.2.3
adobeacrobat_reader8.2.4
adobeacrobat_reader9.0
adobeacrobat_reader9.1
adobeacrobat_reader9.1.1
adobeacrobat_reader9.1.2
adobeacrobat_reader9.1.3
adobeacrobat_reader9.2
adobeacrobat_reader9.3
adobeacrobat_reader9.3.1
adobeacrobat_reader9.3.2
adobeacrobat_reader9.3.3
adobeacrobat_reader9.3.4
adobeacrobat_reader9.4
adobeacrobat_reader10.0
applemac_os_xall versions
microsoftwindowsall versions
adobeacrobat8.0
adobeacrobat8.1
adobeacrobat8.1.1
adobeacrobat8.1.2
adobeacrobat8.1.3
adobeacrobat8.1.4
adobeacrobat8.1.5
adobeacrobat8.1.6
adobeacrobat8.1.7
adobeacrobat8.2
adobeacrobat8.2.1
adobeacrobat8.2.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-4091