← Back

CVE-2014-8452

nvd nist
Published: Dec 10, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected (56)

2 products
Acrobat Reader
Acrobat
1 product
Mac Os X
1 product
Windows
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 10.0.1
Version 10.0.2
Version 10.0.3
Version 10.0
Version 10.1.10
Version 10.1.11
Version 10.1.12
Version 10.1.1
Version 10.1.2
Version 10.1.3
Version 10.1.4
Version 10.1.5
Version 10.1.6
Version 10.1.7
Version 10.1.8
Version 10.1.9
Version 10.1
Version 11.0.01
Version 11.0.02
Version 11.0.03
Version 11.0.04
Version 11.0.05
Version 11.0.06
Version 11.0.07
Version 11.0.08
Version 11.0.09
Version 11.0.0
Configuration B
29 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 10.0.1
Version 10.0.2
Version 10.0.3
Version 10.0
Version 10.1.10
Version 10.1.11
Version 10.1.12
Version 10.1.1
Version 10.1.2
Version 10.1.3
Version 10.1.4
Version 10.1.5
Version 10.1.6
Version 10.1.7
Version 10.1.8
Version 10.1.9
Version 10.1
Version 11.0.1
Version 11.0.2
Version 11.0.3
Version 11.0.4
Version 11.0.5
Version 11.0.6
Version 11.0.7
Version 11.0.8
Version 11.0.9
Version 11.0
All versions
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.