CVE-2011-2438 describes multiple stack-based buffer overflows within the image-parsing library of Adobe Reader and Acrobat versions 8.x, 9.x, and 10.x. This critical vulnerability (CVSS 9.3) allows unauthenticated attackers to execute arbitrary code remotely with medium attack complexity. While the FAUCET Risk Score is high at 85/100, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community or media discussion. Organizations should prioritize patching affected Adobe products to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:8.1:*:*:*:*:*:*:* | ||
8.1.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:8.1.1:*:*:*:*:*:*:* | ||
8.1.2CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:8.1.2:*:*:*:*:*:*:* | ||
8.1.3CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:8.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.