cbcvebase.
CVE-2004-0632
published 2004-07-27

CVE-2004-0632: Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary…

PriorityP334high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.24%
93.7th percentile
Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that is not normally handled by Reader, triggering a buffer overflow.

Affected

4 ranges
VendorProductVersion rangeFixed in
adobeacrobat
adobeacrobat
adobeacrobat_reader
adobeacrobat_reader
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.