The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.
2008-11-05T15:00:14.603
2025-04-09T00:30:58.490
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | adobe | download_manager | * | No |
| Application | adobe | acrobat | ≤ 8.1.2 | Yes |
| Application | adobe | acrobat | ≤ 8.1.2 | Yes |
| Application | adobe | acrobat | ≤ 8.1.2 | Yes |
| Application | adobe | acrobat | 8.1.1 | Yes |
| Application | adobe | acrobat | 8.1.1 | Yes |
| Application | adobe | acrobat | 8.1.1 | Yes |
| Application | adobe | acrobat | 8.1.1 | Yes |
| Application | adobe | acrobat_reader | ≤ 8.0 | Yes |