CVE-2014-0496: Adobe Reader and Acrobat Use-After-Free Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 40% chance of exploitation in the next 30 days.

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

Affected products

  • Adobe Acrobat: from 10.0, before 10.1.9 (fixed in 10.1.9); from 11.0, before 11.0.6 (fixed in 11.0.6)

Published 2014-01-15. Last modified 2026-06-17.