CVE-2004-1153Use of Externally-Controlled Format String in Adobe Acrobat Reader

2 documents2 sources
Severity
10.0CRITICALNVD
EPSS
14.9%
top 5.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 10
Latest updateApr 29

Description

Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDadobe/acrobat_reader6.0, 6.0.2, 8.0+2

Patches

🔴Vulnerability Details

1
GHSA
GHSA-xg26-px52-wxv6: Format string vulnerability in Adobe Acrobat Reader 62022-04-29
CVE-2004-1153 — Adobe Acrobat Reader vulnerability | cvebase