CVE-2008-2042

EUVD-2008-2039
The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
adobeacrobat
𝑥
≤ 8.1.1
adobeacrobat
3.0
adobeacrobat
3.1
adobeacrobat
4.0
adobeacrobat
4.0.5
adobeacrobat
4.0.5a:a
adobeacrobat
4.0.5c:c
adobeacrobat
5.0
adobeacrobat
5.0.5
adobeacrobat
5.0.6
adobeacrobat
5.0.10
adobeacrobat
6.0
adobeacrobat
6.0.1
adobeacrobat
6.0.2
adobeacrobat
6.0.3
adobeacrobat
6.0.4
adobeacrobat
6.0.5
adobeacrobat
6.0.6
adobeacrobat
7.0
adobeacrobat
7.0.1
adobeacrobat
7.0.2
adobeacrobat
7.0.3
adobeacrobat
7.0.4
adobeacrobat
7.0.5
adobeacrobat
7.0.6
adobeacrobat
7.0.7
adobeacrobat
7.0.8
adobeacrobat
7.0.9
adobeacrobat
7.1.0
adobeacrobat
7.1.1
adobeacrobat
7.1.2
adobeacrobat
7.1.3
adobeacrobat
7.1.4
adobeacrobat
8.0
adobeacrobat
8.1
adobeacrobat_reader
𝑥
≤ 8.1.1
adobeacrobat_reader
3.0
adobeacrobat_reader
3.01
adobeacrobat_reader
3.02
adobeacrobat_reader
4.0
adobeacrobat_reader
4.0.5
adobeacrobat_reader
4.0.5a:a
adobeacrobat_reader
4.0.5c:c
adobeacrobat_reader
4.5
adobeacrobat_reader
5.0
adobeacrobat_reader
5.0.5
adobeacrobat_reader
5.0.6
adobeacrobat_reader
5.0.7
adobeacrobat_reader
5.0.9
adobeacrobat_reader
5.0.10
adobeacrobat_reader
5.0.11
adobeacrobat_reader
5.1
adobeacrobat_reader
6.0
adobeacrobat_reader
6.0.1
adobeacrobat_reader
6.0.2
adobeacrobat_reader
6.0.3
adobeacrobat_reader
6.0.4
adobeacrobat_reader
6.0.5
adobeacrobat_reader
6.0.6
adobeacrobat_reader
7.0
adobeacrobat_reader
7.0.1
adobeacrobat_reader
7.0.2
adobeacrobat_reader
7.0.3
adobeacrobat_reader
7.0.4
adobeacrobat_reader
7.0.5
adobeacrobat_reader
7.0.6
adobeacrobat_reader
7.0.7
adobeacrobat_reader
7.0.8
adobeacrobat_reader
7.0.9
adobeacrobat_reader
7.1.0
adobeacrobat_reader
7.1.1
adobeacrobat_reader
7.1.2
adobeacrobat_reader
7.1.3
adobeacrobat_reader
7.1.4
adobeacrobat_reader
8.0
adobeacrobat_reader
8.1
𝑥
= Vulnerable software versions