CVE-2007-5666
published 2008-02-12CVE-2007-5666: Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security…
PriorityP420medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
1.37%
69.1th percentile
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 8.1.1 | — |
| adobe | acrobat_reader | <= 8.1.1 | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6hj-jcpc-rwr6: Untrusted search path vulnerability in Adobe Reader and Acrobat 8
ghsa_unreviewed·2022-05-01·CVSS 9.8
CVE-2007-5666 [CRITICAL] CWE-94 GHSA-f6hj-jcpc-rwr6: Untrusted search path vulnerability in Adobe Reader and Acrobat 8
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.
Red Hat
acroread JavaScript Insecure Libary Search Path
vendor_redhat·2008-02-08·CVSS 6.2
CVE-2007-5666 [MEDIUM] acroread JavaScript Insecure Libary Search Path
acroread JavaScript Insecure Libary Search Path
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.
No detection rules found.
No public exploits indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=655http://secunia.com/advisories/29065http://secunia.com/advisories/29205http://secunia.com/advisories/30840http://security.gentoo.org/glsa/glsa-200803-01.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1http://www.adobe.com/support/security/advisories/apsa08-01.htmlhttp://www.adobe.com/support/security/bulletins/apsb08-13.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0144.htmlhttp://www.us-cert.gov/cas/techalerts/TA08-043A.htmlhttp://www.vupen.com/english/advisories/2008/1966/referenceshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11161http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=655http://secunia.com/advisories/29065http://secunia.com/advisories/29205http://secunia.com/advisories/30840http://security.gentoo.org/glsa/glsa-200803-01.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1http://www.adobe.com/support/security/advisories/apsa08-01.htmlhttp://www.adobe.com/support/security/bulletins/apsb08-13.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0144.htmlhttp://www.us-cert.gov/cas/techalerts/TA08-043A.htmlhttp://www.vupen.com/english/advisories/2008/1966/referenceshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11161
2008-02-12
Published