Vulnerabilities
Vulnerable Software
Adobe:  >> Acrobat  >> 5.0  Security Vulnerabilities
The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.
CVSS Score
9.3
EPSS Score
0.05
Published
2008-05-08
Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSepsWithParams, which triggers memory corruption.
CVSS Score
9.3
EPSS Score
0.146
Published
2008-02-12
CVE-2007-5659
Known exploited
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
CVSS Score
7.8
EPSS Score
0.942
Published
2008-02-12
Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in. NOTE: this issue might be subsumed by CVE-2008-0655.
CVSS Score
9.3
EPSS Score
0.133
Published
2008-02-12
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.
CVSS Score
6.2
EPSS Score
0.014
Published
2008-02-12
CVE-2008-0655
Known exploited
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
CVSS Score
8.8
EPSS Score
0.368
Published
2008-02-07
Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and overwrites a subroutine pointer during rendering.
CVSS Score
9.3
EPSS Score
0.091
Published
2006-12-31
Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, which allows local users to gain privileges by overwriting program files.
CVSS Score
4.6
EPSS Score
0.006
Published
2006-07-12
Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.
CVSS Score
4.6
EPSS Score
0.013
Published
2006-02-02
Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
CVSS Score
7.5
EPSS Score
0.132
Published
2005-08-16


Contact Us

Shodan ® - All rights reserved