Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Reader Apsb07 01 | — | — | Apr 12, 2012 | Jan 3, 2007 |
| Gentoo Linux | — | Upgrade app-text/acroread. | Oct 30, 2017 | Jan 3, 2007 |
| Suse | — | Upgrade acroreadUpgrade suse-release | Feb 17, 2015 | Jan 3, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub