security flaw
Published Jan 3, 2007
4.3
MEDIUMCVSS 2.0
EPSS 46.59%
Description
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."
Affected products
No data.
- ≤ 7.0.8
- 7.0
- 7.0
- 7.0.1
- 7.0.1
- 7.0.2
- 7.0.2
- 7.0.3
- 7.0.3
- 7.0.4
- 7.0.4
- 7.0.5
- 7.0.5
- 7.0.6
- 7.0.6
- 7.0.7
- 7.0.7
- 7.0.8
- 7.0.8
- n/a
- ≤ 7.0.8
- 6.0
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 6.0.5
- 7.0
- 7.0.1
- 7.0.2
- 7.0.3
- 7.0.4
- 7.0.5
- 7.0.6
- 7.0.7
- 7.0.8
No data.
Extras for RHEL 3
acroread-0:7.0.9-1.1.1.EL3
Fixed · RHSA-2007:0021
Extras for RHEL 3
acroread-libs-atk-0:1.8.0-1.el3
Fixed · RHSA-2007:0021
Extras for RHEL 3
acroread-libs-glib2-0:2.4.7-1
Fixed · RHSA-2007:0021
Extras for RHEL 3
acroread-libs-gtk2-0:2.4.13-1.el3
Fixed · RHSA-2007:0021
Extras for RHEL 3
acroread-libs-gtk2-engines-0:2.2.0-1.el3
Fixed · RHSA-2007:0021
Extras for RHEL 3
acroread-libs-pango-0:1.6.0-1.el3
Fixed · RHSA-2007:0021
Extras for RHEL 4
acroread-0:7.0.9-1.2.0.EL4
Fixed · RHSA-2007:0017
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | acroread-0:7.0.9-1.1.1.EL3 | Fixed | RHSA-2007:0021 |
| Extras for RHEL 3 | acroread-libs-atk-0:1.8.0-1.el3 | Fixed | RHSA-2007:0021 |
| Extras for RHEL 3 | acroread-libs-glib2-0:2.4.7-1 | Fixed | RHSA-2007:0021 |
| Extras for RHEL 3 | acroread-libs-gtk2-0:2.4.13-1.el3 | Fixed | RHSA-2007:0021 |
| Extras for RHEL 3 | acroread-libs-gtk2-engines-0:2.2.0-1.el3 | Fixed | RHSA-2007:0021 |
| Extras for RHEL 3 | acroread-libs-pango-0:1.6.0-1.el3 | Fixed | RHSA-2007:0021 |
| Extras for RHEL 4 | acroread-0:7.0.9-1.2.0.EL4 | Fixed | RHSA-2007:0017 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (28 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 46.59% (0.46592) | 98.79th | v5 (v2026.06.15) |
| Aug 1, 2026 | 46.59% (0.46592) | 98.70th | v5 (v2026.06.15) |
| Jun 15, 2026 | 45.26% (0.45260) | 98.62th | v5 (v2026.06.15) |
| May 31, 2026 | 58.96% (0.58957) | 98.26th | v4 (v2025.03.14) |
| May 22, 2026 | 50.14% (0.50136) | 97.87th | v4 (v2025.03.14) |
| Aug 22, 2025 | 61.36% (0.61361) | 98.25th | v4 (v2025.03.14) |
| May 11, 2025 | 63.94% (0.63944) | 98.29th | v4 (v2025.03.14) |
| Mar 30, 2025 | 68.97% (0.68975) | 98.52th | v4 (v2025.03.14) |
| Mar 29, 2025 | 70.37% (0.70370) | 98.21th | v4 (v2025.03.14) |
| Mar 20, 2025 | 68.97% (0.68975) | 98.56th | v4 (v2025.03.14) |
| Mar 17, 2025 | 72.37% (0.72367) | 98.67th | v4 (v2025.03.14) |
| Dec 17, 2024 | 88.67% (0.88674) | 98.96th | v3 (v2023.03.01) |
| Dec 12, 2024 | 92.66% (0.92657) | 99.12th | v3 (v2023.03.01) |
| Jul 15, 2024 | 92.19% (0.92191) | 98.98th | v3 (v2023.03.01) |
| May 28, 2024 | 92.50% (0.92495) | 98.98th | v3 (v2023.03.01) |
| Apr 8, 2024 | 92.13% (0.92128) | 98.90th | v3 (v2023.03.01) |
| Feb 29, 2024 | 92.31% (0.92312) | 98.89th | v3 (v2023.03.01) |
| Jan 22, 2024 | 90.51% (0.90506) | 98.59th | v3 (v2023.03.01) |
| Dec 15, 2023 | 93.53% (0.93527) | 98.89th | v3 (v2023.03.01) |
| Nov 7, 2023 | 96.34% (0.96335) | 99.39th | v3 (v2023.03.01) |
| Sep 30, 2023 | 96.69% (0.96686) | 99.51th | v3 (v2023.03.01) |
| Aug 23, 2023 | 96.89% (0.96890) | 99.58th | v3 (v2023.03.01) |
| Apr 30, 2023 | 96.94% (0.96940) | 99.53th | v3 (v2023.03.01) |
| Mar 25, 2023 | 96.99% (0.96991) | 99.53th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.92% (0.96921) | 99.48th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
References (48)
- http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf x_refsource_MISC
- http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html x_refsource_CONFIRM
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 vendor-advisoryx_refsource_HP
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/23483 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23691 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23812 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23877 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23882 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24457 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24533 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/33754 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-200701-16.xml vendor-advisoryx_refsource_GENTOO
- http://securityreason.com/securityalert/2090 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1017469 vdb-entryx_refsource_SECTRACK
- http://securitytracker.com/id?1023007 vdb-entryx_refsource_SECTRACK
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131 vendor-advisoryx_refsource_SLACKWARE
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1 vendor-advisoryx_refsource_SUNALERT
- http://www.adobe.com/support/security/advisories/apsa07-01.html x_refsource_CONFIRMVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa07-02.html x_refsource_CONFIRM
- http://www.adobe.com/support/security/bulletins/apsb07-01.html x_refsource_CONFIRM
- http://www.adobe.com/support/security/bulletins/apsb09-15.html x_refsource_CONFIRM
- http://www.disenchant.ch/blog/hacking-with-browser-plugins/34 x_refsource_MISCExploit
- http://www.gnucitizen.org/blog/danger-danger-danger/ x_refsource_CONFIRMExploitVendor Advisory
- http://www.gnucitizen.org/blog/universal-pdf-xss-after-party x_refsource_MISC
- http://www.kb.cert.org/vuls/id/815960 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mozilla.org/security/announce/2007/mfsa2007-02.html x_refsource_CONFIRM
- http://www.redhat.com/support/errata/RHSA-2007-0021.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/455790/100/0/threaded mailing-listx_refsource_BUGTRAQExploit
- http://www.securityfocus.com/archive/1/455800/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/455801/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/455831/100/0/threaded mailing-listx_refsource_BUGTRAQExploit
- http://www.securityfocus.com/archive/1/455836/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/455906/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/21858 vdb-entryx_refsource_BID
- http://www.us-cert.gov/cas/techalerts/TA09-286B.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2007/0032 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/0957 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/2898 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.wisec.it/vulns.php?page=9 x_refsource_MISCExploitPatch
- https://access.redhat.com/security/cve/CVE-2007-0045 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618261 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31271 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2007-0045
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6487 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9693 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2007-0017.html vendor-advisoryx_refsource_REDHAT
- https://www.cve.org/CVERecord?id=CVE-2007-0045
Change history (0)
No recorded changes yet.