CVE-2004-1153
10
CVSS SCORE
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
Description
Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
C
Integrity
C
Availability
C
Affected Software Configurations
- a adobe acrobat_reader 6.0 * * * * * * *
- a adobe acrobat_reader 6.0.2 * * * * * * *
- a adobe acrobat_reader 8.0 * * * * * * *
Weaknesses (CWE)
- NVD-CWE-Other
References & External Links
- http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679
- http://www.idefense.com/application/poi/display?id=163&type=vulnerabilities
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18478
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2919
- http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679
- http://www.idefense.com/application/poi/display?id=163&type=vulnerabilities
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18478
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2919