CVE-2008-4817
published 2008-11-05CVE-2008-4817: The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.91%
94.7th percentile
The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 8.1.2 | — |
| adobe | acrobat | — | — |
| adobe | acrobat_reader | <= 8.0 | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Reader: Download Manager input validation flaw
vendor_redhat·2008-11-04·CVSS 9.3
CVE-2008-4817 [CRITICAL] CWE-20 Reader: Download Manager input validation flaw
Reader: Download Manager input validation flaw
The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.
GHSA
GHSA-p376-gg94-fq5h: Stack-based buffer overflow in the getPlus ActiveX control in gp
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2008-5364 [CRITICAL] CWE-119 GHSA-p376-gg94-fq5h: Stack-based buffer overflow in the getPlus ActiveX control in gp
Stack-based buffer overflow in the getPlus ActiveX control in gp.ocx 1.2.2.50 in NOS Microsystems getPlus Download Manager, as used for the Adobe Reader 8.1 installation process and other downloads, allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2008-4817.
GHSA
GHSA-768r-jccv-hcw3: The Download Manager in Adobe Acrobat Professional and Reader 8
ghsa_unreviewed·2022-05-14
CVE-2008-4817 [HIGH] CWE-20 GHSA-768r-jccv-hcw3: The Download Manager in Adobe Acrobat Professional and Reader 8
The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.
No detection rules found.
No public exploits indexed.
http://download.oracle.com/sunalerts/1019937.1.htmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=756http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://osvdb.org/49541http://secunia.com/advisories/32700http://secunia.com/advisories/32872http://www.adobe.com/support/security/bulletins/apsb08-19.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0974.htmlhttp://www.securitytracker.com/id?1021140http://www.us-cert.gov/cas/techalerts/TA08-309A.htmlhttp://www.vupen.com/english/advisories/2008/3001http://www.vupen.com/english/advisories/2009/0098http://download.oracle.com/sunalerts/1019937.1.htmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=756http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://osvdb.org/49541http://secunia.com/advisories/32700http://secunia.com/advisories/32872http://www.adobe.com/support/security/bulletins/apsb08-19.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0974.htmlhttp://www.securitytracker.com/id?1021140http://www.us-cert.gov/cas/techalerts/TA08-309A.htmlhttp://www.vupen.com/english/advisories/2008/3001http://www.vupen.com/english/advisories/2009/0098
2008-11-05
Published