6.8

CVE-2007-0104

Exploit

The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.

Data is provided by the National Vulnerability Database (NVD)
XpdfXpdf Version3.0
XpdfXpdf Version3.0.1
XpdfXpdf Version3.0.1_pl1
XpdfXpdf Version3.0.1_pl2
XpdfXpdf Version3.0_pl2
KdeKde Version3.2
KdeKde Version3.2.1
KdeKde Version3.2.2
KdeKde Version3.2.3
KdeKde Version3.3
KdeKde Version3.3.1
KdeKde Version3.3.2
KdeKde Version3.4
KdeKde Version3.4.1
KdeKde Version3.4.2
KdeKde Version3.4.3
KdeKde Version3.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 19.01% 0.951
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.