CVE-2010-1240

Scores

EPSS

0.920high92.0%
0%20%40%60%80%100%

Percentile: 92.0%

CVSS

6.8medium2.0
0246810

CVSS Score: 6.8/10

All CVSS Scores

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvdredhat

CWEs

CWE-264

Related Vulnerabilities

Exploits

Exploit ID: 11987

Source: exploitdb

URL: https://www.exploit-db.com/exploits/11987

Exploit ID: 16671

Source: exploitdb

URL: https://www.exploit-db.com/exploits/16671

Exploit ID: 16682

Source: exploitdb

URL: https://www.exploit-db.com/exploits/16682

Exploit ID: CVE-2010-1240

Source: github-poc

URL: https://github.com/12345qwert123456/CVE-2010-1240

Vulnerable Software (3)

Type: Configuration

Product: acroread

Operating System: rhel

Trait:
{  "fixed": "9.3.3-2.el4"}

Source: redhat

Type: Configuration

Product: acroread

Operating System: rhel

Trait:
{  "fixed": "9.3.3-1.el5"}

Source: redhat

Type: Configuration

Vendor: *

Product: acrobat_reader

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:adobe:acrobat_reader:9.3.1:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

End of list