Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5108 and CVE-2015-5109.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CAdobe Acrobat
APPAdobe10.0 – 10.1.1411.0.0 – 11.0.11Adobe Acrobat DC
APPAdobe15.006.30033 – 15.006.30060 (excl.)15.007.20033 – 15.008.20082 (excl.)Adobe Acrobat Reader
APPAdobe10.0 – 10.1.1411.0.0 – 11.0.11Adobe Acrobat Reader Dc
APPAdobe15.006.30033 – 15.006.30060 (excl.)15.007.20033 – 15.008.20082 (excl.)Apple macOS
OSAppleall versionsMicrosoft Windows
OSMicrosoftall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelniania w Screen Sharing na macOS
CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP