CVE-2014-9161
Summary
| CVE | CVE-2014-9161 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-30 11:59:50 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | CoolType.dll in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows, and 10.x through 10.1.13 and 11.x through 11.0.10 on OS X, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted PDF document. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Acrobat | 10.0 | All | All | All |
| Application | Adobe | Acrobat | 10.0.1 | All | All | All |
| Application | Adobe | Acrobat | 10.0.2 | All | All | All |
| Application | Adobe | Acrobat | 10.0.3 | All | All | All |
| Application | Adobe | Acrobat | 10.1 | All | All | All |
| Application | Adobe | Acrobat | 10.1.1 | All | All | All |
| Application | Adobe | Acrobat | 10.1.10 | All | All | All |
| Application | Adobe | Acrobat | 10.1.11 | All | All | All |
| Application | Adobe | Acrobat | 10.1.12 | All | All | All |
| Application | Adobe | Acrobat | 10.1.2 | All | All | All |
| Application | Adobe | Acrobat | 10.1.3 | All | All | All |
| Application | Adobe | Acrobat | 10.1.4 | All | All | All |
| Application | Adobe | Acrobat | 10.1.5 | All | All | All |
| Application | Adobe | Acrobat | 10.1.6 | All | All | All |
| Application | Adobe | Acrobat | 10.1.7 | All | All | All |
| Application | Adobe | Acrobat | 10.1.8 | All | All | All |
| Application | Adobe | Acrobat | 10.1.9 | All | All | All |
| Application | Adobe | Acrobat | 11.0 | All | All | All |
| Application | Adobe | Acrobat | 11.0.1 | All | All | All |
| Application | Adobe | Acrobat | 11.0.2 | All | All | All |
| Application | Adobe | Acrobat | 11.0.3 | All | All | All |
| Application | Adobe | Acrobat | 11.0.4 | All | All | All |
| Application | Adobe | Acrobat | 11.0.5 | All | All | All |
| Application | Adobe | Acrobat | 11.0.6 | All | All | All |
| Application | Adobe | Acrobat | 11.0.7 | All | All | All |
| Application | Adobe | Acrobat | 11.0.8 | All | All | All |
| Application | Adobe | Acrobat | 11.0.9 | All | All | All |
| Application | Adobe | Acrobat Reader | 10.1.13 | All | All | All |
| Application | Adobe | Acrobat Reader | 11.0.10 | All | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Adobe Security Bulletin | af854a3a-2127-422b-91ae-364da2661108 | helpx.adobe.com | Vendor Advisory |
| Adobe Reader and Acrobat Bugs Let Remote Users Execute Arbitrary Code, Obtain Information, any Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Issue 149 - google-security-research - Adobe Reader X and XI for Windows out-of-bounds read in CoolType.dll - Google Security Research - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| Adobe Reader X / XI Out Of Bounds Read ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| Adobe Reader and Acrobat Multiple Memory Corruption Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.