CVE-2007-0048
Last modified
CVE-2007-0048 is a vulnerability of currently unknown severity. Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue.". EPSS estimates a 31.51% chance of exploitation in the next 30 days.
Description
Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat | <= 7.0.8 |
| Adobe | Acrobat | 7.0 |
| Adobe | Acrobat | 7.0.1 |
| Adobe | Acrobat | 7.0.2 |
| Adobe | Acrobat | 7.0.3 |
| Adobe | Acrobat | 7.0.4 |
| Adobe | Acrobat | 7.0.5 |
| Adobe | Acrobat | 7.0.6 |
| Adobe | Acrobat | 7.0.7 |
| Adobe | Acrobat | 7.0.8 |
| Adobe | Acrobat 3d | All versions |
| Adobe | Acrobat Reader | <= 7.0.8 |
| Adobe | Acrobat Reader | 6.0 |
| Adobe | Acrobat Reader | 6.0.1 |
| Adobe | Acrobat Reader | 6.0.2 |
| Adobe | Acrobat Reader | 6.0.3 |
| Adobe | Acrobat Reader | 6.0.4 |
| Adobe | Acrobat Reader | 6.0.5 |
| Adobe | Acrobat Reader | 7.0 |
| Adobe | Acrobat Reader | 7.0.1 |
| Adobe | Acrobat Reader | 7.0.2 |
| Adobe | Acrobat Reader | 7.0.3 |
| Adobe | Acrobat Reader | 7.0.4 |
| Adobe | Acrobat Reader | 7.0.5 |
| Adobe | Acrobat Reader | 7.0.6 |
| Adobe | Acrobat Reader | 7.0.7 |
| Adobe | Acrobat Reader | 7.0.8 |
References
- http://www.us-cert.gov/cas/techalerts/TA09-286B.htmlUS Government Resource
- http://www.wisec.it/vulns.php?page=9Exploit, Patch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-286B.htmlUS Government Resource
- http://www.wisec.it/vulns.php?page=9Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0048?
How severe is CVE-2007-0048?
How do I fix CVE-2007-0048?
Are you affected by CVE-2007-0048?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
