CVE-2013-0732
critical
CVSS v3
—
CVSS v2
9.3
VIR risk
9.3
Description
Heap-based buffer overflow in PDFCore8.dll in Nuance PDF Reader before 8.1 allows remote attackers to execute arbitrary code via crafted font table directory values in a TTF file, related to naming table entries.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: PSIRT-CNA@flexerasoftware.com — http://secunia.com/advisories/51943
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| nuance | pdf_reader | {"endIncluding":"7.0"} | |
| nuance | pdf_reader | 6.0 | |
References
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.