Lucene search

K
nvd[email protected]NVD:CVE-2007-0045
HistoryJan 03, 2007 - 9:28 p.m.

CVE-2007-0045

2007-01-0321:28:00
CWE-79
web.nvd.nist.gov
5

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.922

Percentile

99.0%

Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka “Universal XSS (UXSS).”

Affected configurations

Nvd
Node
adobeacrobatRange7.0.8elements
OR
adobeacrobatMatch7.0professional
OR
adobeacrobatMatch7.0standard
OR
adobeacrobatMatch7.0.1professional
OR
adobeacrobatMatch7.0.1standard
OR
adobeacrobatMatch7.0.2professional
OR
adobeacrobatMatch7.0.2standard
OR
adobeacrobatMatch7.0.3professional
OR
adobeacrobatMatch7.0.3standard
OR
adobeacrobatMatch7.0.4professional
OR
adobeacrobatMatch7.0.4standard
OR
adobeacrobatMatch7.0.5professional
OR
adobeacrobatMatch7.0.5standard
OR
adobeacrobatMatch7.0.6professional
OR
adobeacrobatMatch7.0.6standard
OR
adobeacrobatMatch7.0.7professional
OR
adobeacrobatMatch7.0.7standard
OR
adobeacrobatMatch7.0.8professional
OR
adobeacrobatMatch7.0.8standard
OR
adobeacrobat_3d
OR
adobeacrobat_readerRange7.0.8
OR
adobeacrobat_readerMatch6.0
OR
adobeacrobat_readerMatch6.0.1
OR
adobeacrobat_readerMatch6.0.2
OR
adobeacrobat_readerMatch6.0.3
OR
adobeacrobat_readerMatch6.0.4
OR
adobeacrobat_readerMatch6.0.5
OR
adobeacrobat_readerMatch7.0
OR
adobeacrobat_readerMatch7.0.1
OR
adobeacrobat_readerMatch7.0.2
OR
adobeacrobat_readerMatch7.0.3
OR
adobeacrobat_readerMatch7.0.4
OR
adobeacrobat_readerMatch7.0.5
OR
adobeacrobat_readerMatch7.0.6
OR
adobeacrobat_readerMatch7.0.7
OR
adobeacrobat_readerMatch7.0.8

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.922

Percentile

99.0%