VulnerabilityModified
CVE-2003-0434
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
HIGH 7.5EPSS 40.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 40.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 40.94% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- adobe/acrobat · xpdf/xpdf · mandrakesoft/mandrake linux · mandrakesoft/mandrake linux corporate server · redhat/enterprise linux · redhat/linux · redhat/linux advanced workstation
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005719.html
- http://marc.info/?l=bugtraq&m=105777963019186&w=2
- http://secunia.com/advisories/9037
- http://secunia.com/advisories/9038
- http://www.kb.cert.org/vuls/id/200132US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:071
- http://www.redhat.com/support/errata/RHSA-2003-196.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-197.htmlPatch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A664
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005719.html
- http://marc.info/?l=bugtraq&m=105777963019186&w=2
- http://secunia.com/advisories/9037
- http://secunia.com/advisories/9038
- http://www.kb.cert.org/vuls/id/200132US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:071
- http://www.redhat.com/support/errata/RHSA-2003-196.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-197.htmlPatch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A664
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.