CVE-2012-1530: Adobe Acrobat
High severity, CVSS 10.0. EPSS: 8.6% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing an XSL file that triggers memory corruption when the lang function processes XML data with a crafted node-set.
Affected products
- Adobe Acrobat: version 9.0 only; version 9.1 only; version 9.1.1 only; version 9.1.2 only; version 9.1.3 only; version 9.2 only; …
- Adobe Acrobat Reader: version 9.0 only; version 9.1 only; version 9.1.1 only; version 9.1.2 only; version 9.1.3 only; version 9.2 only; …
Published 2013-01-10. Last modified 2026-06-16.