Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4817

Опубликовано: 05 нояб. 2008
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:adobe:download_manager:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:adobe:acrobat:*:unknown:3d:*:*:*:*:*
Версия до 8.1.2 (включая)
cpe:2.3:a:adobe:acrobat:*:unknown:professional:*:*:*:*:*
Версия до 8.1.2 (включая)
cpe:2.3:a:adobe:acrobat:*:unknown:standard:*:*:*:*:*
Версия до 8.1.2 (включая)
cpe:2.3:a:adobe:acrobat:8.1.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:8.1.1:unknown:3d:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:8.1.1:unknown:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:8.1.1:unknown:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Версия до 8.0 (включая)

EPSS

Процентиль: 94%
0.17067
Средний

9.3 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 17 лет назад

The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.

redhat
около 17 лет назад

The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.

github
больше 3 лет назад

The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.

EPSS

Процентиль: 94%
0.17067
Средний

9.3 Critical

CVSS2

Дефекты

CWE-20