CVE-2008-2042

The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
adobeacrobat
𝑥
≤ 8.1.1
adobeacrobat
3.0
adobeacrobat
3.1
adobeacrobat
4.0
adobeacrobat
4.0.5
adobeacrobat
4.0.5a:a
adobeacrobat
4.0.5c:c
adobeacrobat
5.0
adobeacrobat
5.0.5
adobeacrobat
5.0.6
adobeacrobat
5.0.10
adobeacrobat
6.0
adobeacrobat
6.0.1
adobeacrobat
6.0.2
adobeacrobat
6.0.3
adobeacrobat
6.0.4
adobeacrobat
6.0.5
adobeacrobat
6.0.6
adobeacrobat
7.0
adobeacrobat
7.0.1
adobeacrobat
7.0.2
adobeacrobat
7.0.3
adobeacrobat
7.0.4
adobeacrobat
7.0.5
adobeacrobat
7.0.6
adobeacrobat
7.0.7
adobeacrobat
7.0.8
adobeacrobat
7.0.9
adobeacrobat
7.1.0
adobeacrobat
7.1.1
adobeacrobat
7.1.2
adobeacrobat
7.1.3
adobeacrobat
7.1.4
adobeacrobat
8.0
adobeacrobat
8.1
adobeacrobat_reader
𝑥
≤ 8.1.1
adobeacrobat_reader
3.0
adobeacrobat_reader
3.01
adobeacrobat_reader
3.02
adobeacrobat_reader
4.0
adobeacrobat_reader
4.0.5
adobeacrobat_reader
4.0.5a:a
adobeacrobat_reader
4.0.5c:c
adobeacrobat_reader
4.5
adobeacrobat_reader
5.0
adobeacrobat_reader
5.0.5
adobeacrobat_reader
5.0.6
adobeacrobat_reader
5.0.7
adobeacrobat_reader
5.0.9
adobeacrobat_reader
5.0.10
adobeacrobat_reader
5.0.11
adobeacrobat_reader
5.1
adobeacrobat_reader
6.0
adobeacrobat_reader
6.0.1
adobeacrobat_reader
6.0.2
adobeacrobat_reader
6.0.3
adobeacrobat_reader
6.0.4
adobeacrobat_reader
6.0.5
adobeacrobat_reader
6.0.6
adobeacrobat_reader
7.0
adobeacrobat_reader
7.0.1
adobeacrobat_reader
7.0.2
adobeacrobat_reader
7.0.3
adobeacrobat_reader
7.0.4
adobeacrobat_reader
7.0.5
adobeacrobat_reader
7.0.6
adobeacrobat_reader
7.0.7
adobeacrobat_reader
7.0.8
adobeacrobat_reader
7.0.9
adobeacrobat_reader
7.1.0
adobeacrobat_reader
7.1.1
adobeacrobat_reader
7.1.2
adobeacrobat_reader
7.1.3
adobeacrobat_reader
7.1.4
adobeacrobat_reader
8.0
adobeacrobat_reader
8.1
𝑥
= Vulnerable software versions