CVE-2007-1377
Last modified
CVE-2007-1377 is a vulnerability of currently unknown severity. AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027 and CVE-2006-6236.. EPSS estimates a 19.61% chance of exploitation in the next 30 days.
Description
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027 and CVE-2006-6236.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat Reader | 8.0 |
| Mozilla | Firefox | 2.0.0.3 |
| Netscape | Navigator | All versions |
| Opera | Opera Browser | 9.2 |
References
- http://www.securityfocus.com/bid/22856Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/data/vulnerabilities/exploits/22856.htmlBroken Link, Exploit, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32896Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/22856Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/data/vulnerabilities/exploits/22856.htmlBroken Link, Exploit, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32896Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1377?
How severe is CVE-2007-1377?
How do I fix CVE-2007-1377?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1371Multiple buffer overflows in Conquest 8.2a and earlier (1) a…
- CVE-2007-1372PHP remote file inclusion vulnerability in styles/internal/h…
- CVE-2007-1373Stack-based buffer overflow in Mercury/32 (aka Mercury Mail …
- CVE-2007-1374Cross-site scripting (XSS) vulnerability in pop_profile.asp …
- CVE-2007-1375Integer overflow in the substr_compare function in PHP 5.2.1…
- CVE-2007-1376The shmop functions in PHP before 4.4.5, and before 5.2.1 in…
- CVE-2007-1378The ovrimos_longreadlen function in the Ovrimos extension fo…
- CVE-2007-1379The ovrimos_close function in the Ovrimos extension for PHP …
- CVE-2007-1380The php_binary serialization handler in the session extensio…
- CVE-2007-1381The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and …
- CVE-2007-1382The PHP COM extensions for PHP on Windows systems allow cont…
- CVE-2007-1383Integer overflow in the 16 bit variable reference counter in…9.8
Are you affected by CVE-2007-1377?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
