CVE-2005-2470
- EPSS 5.58%
- Published 16.08.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
CVE-2005-1306
- EPSS 16.06%
- Published 15.06.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
- EPSS 1.65%
- Published 12.10.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary directory.
CVE-2004-0629
- EPSS 20.76%
- Published 28.09.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long str...
CVE-2004-0632
- EPSS 23.15%
- Published 27.07.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that is not normally handled by Reader, triggering a bu...
CVE-2003-0434
- EPSS 29.87%
- Published 24.07.2003 04:00:00
- Last modified 03.04.2025 01:03:51
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
CVE-2003-0284
- EPSS 1.22%
- Published 16.06.2003 04:00:00
- Last modified 03.04.2025 01:03:51
Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.
CVE-2002-0030
- EPSS 0.22%
- Published 02.04.2003 05:00:00
- Last modified 03.04.2025 01:03:51
The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe.
CVE-2000-0713
- EPSS 5.13%
- Published 20.10.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.