VULNERABILITY INTELLIGENCE
CVE-2016-4091
CVSS score9.8 CRITICAL
EPSS probability9.87%
CISA KEVNot currently listed
Published2016-05-11
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4092.
Weakness classification
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Primary references
- psirt@adobe.com — Third Party Advisory, VDB Entry
- psirt@adobe.com — Third Party Advisory, VDB Entry
- psirt@adobe.com — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Vendor Advisory