peter bassill · operator
$ cve CVE-2007-0046 JSON

CVE-2007-0046 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 55.9% (pctl 99)

Patch early

A public exploit exists.

Description

Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS55.92% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2007-01-03
Last modified2026-06-16

Affected (1)

VendorProduct
adobeacrobat reader

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD