Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-0045
Description:Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-0045
BugTraq ID: 21858
http://www.securityfocus.com/bid/21858
Bugtraq: 20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/455801/100/0/threaded
Bugtraq: 20070103 RE: [WEB SECURITY] Universal XSS with PDF files: highly dangerous (Google Search)
http://www.securityfocus.com/archive/1/455836/100/0/threaded
Bugtraq: 20070103 Re: Universal XSS with PDF files: highly dangerous (Google Search)
http://www.securityfocus.com/archive/1/455800/100/0/threaded
Bugtraq: 20070103 Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous (Google Search)
http://www.securityfocus.com/archive/1/455831/100/0/threaded
Bugtraq: 20070103 Universal XSS with PDF files: highly dangerous (Google Search)
http://www.securityfocus.com/archive/1/455790/100/0/threaded
Bugtraq: 20070104 Universal PDF XSS After Party (Google Search)
http://www.securityfocus.com/archive/1/455906/100/0/threaded
Cert/CC Advisory: TA09-286B
http://www.us-cert.gov/cas/techalerts/TA09-286B.html
CERT/CC vulnerability note: VU#815960
http://www.kb.cert.org/vuls/id/815960
http://security.gentoo.org/glsa/glsa-200701-16.xml
HPdes Security Advisory: HPSBUX02153
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
HPdes Security Advisory: SSRT061181
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
http://www.disenchant.ch/blog/hacking-with-browser-plugins/34
http://www.gnucitizen.org/blog/universal-pdf-xss-after-party
http://www.wisec.it/vulns.php?page=9
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6487
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9693
RedHat Security Advisories: RHSA-2007:0017
https://rhn.redhat.com/errata/RHSA-2007-0017.html
RedHat Security Advisories: RHSA-2007:0021
http://www.redhat.com/support/errata/RHSA-2007-0021.html
http://securitytracker.com/id?1017469
http://securitytracker.com/id?1023007
http://secunia.com/advisories/23483
http://secunia.com/advisories/23691
http://secunia.com/advisories/23812
http://secunia.com/advisories/23877
http://secunia.com/advisories/23882
http://secunia.com/advisories/24457
http://secunia.com/advisories/24533
http://secunia.com/advisories/33754
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131
http://securityreason.com/securityalert/2090
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1
SuSE Security Announcement: SUSE-SA:2007:011 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
http://www.vupen.com/english/advisories/2007/0032
http://www.vupen.com/english/advisories/2007/0957
http://www.vupen.com/english/advisories/2009/2898
XForce ISS Database: adobe-acrobat-pdf-xss(31271)
https://exchange.xforce.ibmcloud.com/vulnerabilities/31271




© 1998-2025 E-Soft Inc. All rights reserved.