Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp3v-35cv-hc65

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.

The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.

EPSS

Процентиль: 89%
0.04475
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 18 лет назад

The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.

EPSS

Процентиль: 89%
0.04475
Низкий

Дефекты

CWE-20