CVE-2004-0629
published 2004-09-28CVE-2004-0629: Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.07%
93.5th percentile
Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CAPEC
Embedding NULL Bytes
mitre_capec
[HIGH] Embedding NULL Bytes
CAPEC-52: Embedding NULL Bytes
An adversary embeds one or more null bytes in input to the target software. This attack relies on the usage of a null-valued byte as a string terminator in many environments. The goal is for certain components of the target software to stop processing the input when it encounters the null byte(s).
Execution Flow:
Step 1 [Explore]: [Survey the application for user-controllable inputs] Using a browser, an automated tool or by inspecting the application, an adversary records all entry points to the application.
Technique: Use a spidering tool to follow and record all links and analyze the web pages to find entry points. Make special note of any links that include parameters in the URL.
Technique: Use a proxy tool to record all user input entry points visited d
http://www.adobe.com/support/techdocs/330527.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200408-14.xmlhttp://www.idefense.com/application/poi/display?id=126&type=vulnerabilitieshttp://www.securityfocus.com/bid/10947https://exchange.xforce.ibmcloud.com/vulnerabilities/16998http://www.adobe.com/support/techdocs/330527.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200408-14.xmlhttp://www.idefense.com/application/poi/display?id=126&type=vulnerabilitieshttp://www.securityfocus.com/bid/10947https://exchange.xforce.ibmcloud.com/vulnerabilities/16998
2004-09-28
Published