CVE-2007-0044
Last modified
CVE-2007-0044 is a vulnerability of currently unknown severity. Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding.". EPSS estimates a 55.47% chance of exploitation in the next 30 days.
Description
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat | <= 7.0.8 |
| Adobe | Acrobat | 7.0 |
| Adobe | Acrobat | 7.0.1 |
| Adobe | Acrobat | 7.0.2 |
| Adobe | Acrobat | 7.0.3 |
| Adobe | Acrobat | 7.0.4 |
| Adobe | Acrobat | 7.0.5 |
| Adobe | Acrobat | 7.0.6 |
| Adobe | Acrobat | 7.0.7 |
| Adobe | Acrobat | 7.0.8 |
| Adobe | Acrobat 3d | All versions |
| Adobe | Acrobat Reader | <= 7.0.8 |
| Adobe | Acrobat Reader | 6.0 |
| Adobe | Acrobat Reader | 6.0.1 |
| Adobe | Acrobat Reader | 6.0.2 |
| Adobe | Acrobat Reader | 6.0.3 |
| Adobe | Acrobat Reader | 6.0.4 |
| Adobe | Acrobat Reader | 6.0.5 |
| Adobe | Acrobat Reader | 7.0 |
| Adobe | Acrobat Reader | 7.0.1 |
| Adobe | Acrobat Reader | 7.0.2 |
| Adobe | Acrobat Reader | 7.0.3 |
| Adobe | Acrobat Reader | 7.0.4 |
| Adobe | Acrobat Reader | 7.0.5 |
| Adobe | Acrobat Reader | 7.0.6 |
| Adobe | Acrobat Reader | 7.0.7 |
| Adobe | Acrobat Reader | 7.0.8 |
References
- http://secunia.com/advisories/23882Vendor Advisory
- http://secunia.com/advisories/29065Vendor Advisory
- http://securityreason.com/securityalert/2090Vendor Advisory
- http://www.wisec.it/vulns.php?page=9Exploit, Patch
- http://secunia.com/advisories/23882Vendor Advisory
- http://secunia.com/advisories/29065Vendor Advisory
- http://securityreason.com/securityalert/2090Vendor Advisory
- http://www.wisec.it/vulns.php?page=9Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0044?
How severe is CVE-2007-0044?
How do I fix CVE-2007-0044?
Are you affected by CVE-2007-0044?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
