CVE-2007-5659
KEV
🔴 Łataj teraz
Przepełnienie bufora w Adobe Reader i Acrobat umożliwia zdalne wykonanie kodu przez złośliwy PDF.
CVSS
7.8
EPSS
93.1%
Exploit
weaponized
Vendor
adobe
Opis źródłowy (NVD)
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
buffer-overflow
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 93.1% |
| Opublikowano (NVD) | 2008-02-12 19:00:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-04-21 18:56:04 UTC |
Referencje
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=657 (cve@mitre.org) [Broken Link]
- http://secunia.com/advisories/29065 (cve@mitre.org) [Broken Link]
- http://secunia.com/advisories/29205 (cve@mitre.org) [Broken Link]
- http://secunia.com/advisories/30840 (cve@mitre.org) [Broken Link]
- http://security.gentoo.org/glsa/glsa-200803-01.xml (cve@mitre.org) [Third Party Advisory]
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1 (cve@mitre.org) [Broken Link]
- http://www.adobe.com/support/security/advisories/apsa08-01.html (cve@mitre.org) [Vendor Advisory]
- http://www.adobe.com/support/security/bulletins/apsb08-13.html (cve@mitre.org) [Vendor Advisory]
- http://www.kb.cert.org/vuls/id/666281 (cve@mitre.org) [Third Party Advisory, US Government Resource]
- http://www.redhat.com/support/errata/RHSA-2008-0144.html (cve@mitre.org) [Broken Link]
- http://www.us-cert.gov/cas/techalerts/TA08-043A.html (cve@mitre.org) [Broken Link, Third Party Advisory, US Government Resource]
- http://www.vupen.com/english/advisories/2008/1966/references (cve@mitre.org) [Broken Link]
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9813 (cve@mitre.org) [Broken Link]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2007-5659 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]