AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-16396

HIGH · CVSS 8.8 EPSS 12.85% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-12-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2017-16396
Severity
HIGH
CVSS
8.8
EPSS
12.85%

Original NVD Description

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the TIFF processing module. Crafted input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.