SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-0048

Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial…

MEDIUM 5.0EPSS 32.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 32.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
32.61% probability · 98th percentile
CISA KEV
Not listed
Affected
adobe/acrobat · adobe/acrobat 3d · adobe/acrobat reader
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.