CVE-2013-3357

CRITICAL

Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabil...

Affects 4 products across 3 vendors.

BCS7.94
CVSS 2.010.0
EPSS12.8%
Percentile96th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-189: CWE-189
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2013. A critical vulnerability affects Adobe systems (CVE-2013-3357). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2013-GLOBAL-094878-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2013-3357?
This vulnerability was disclosed in 2013. A critical vulnerability affects Adobe systems (CVE-2013-3357). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2013-3357?
CVE-2013-3357 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 12.8%.
Is CVE-2013-3357 actively exploited?
No confirmed active exploitation of CVE-2013-3357 as of 2026-05-30.
How do I remediate CVE-2013-3357?
Priority: MEDIUM. Advisory: http://www.adobe.com/support/security/bulletins/apsb13-22.html PSIRT: [email protected]
What systems are affected by CVE-2013-3357?
CVE-2013-3357 affects: Adobe, Adobe, Apple, Microsoft.
Vulnerability Details
CVE IDCVE-2013-3357
BSIDBS-2013-GLOBAL-094878-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2013-09-12
Last Modified2026-04-29
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3358.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3358. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Adobe Acrobat Reader
Adobe Acrobat
Apple Mac Os X
Microsoft Windows
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 4710 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash32c203842e1d435ae4efcc00fd2289cc5c6bc6fc11785b7e6286f44030116c331c3120119b2824677d3b49f0f7651fa69c64b02018e150c3f6b64a0284bdf36b
Related CVEs affecting Adobe
CVE-2015-5101 10.0 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.15 ... CVE-2015-6691 10.0 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 ... CVE-2004-1152 10.0 Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 fo... CVE-2004-1153 10.0 Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allow... CVE-2026-48282 10.0 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper L...
View all Adobe CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →