Back

CVE-2004-1153

Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.

Published: Jan 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
adobe acrobat_reader 6.0
adobe acrobat_reader 6.0.2
adobe acrobat_reader 8.0

GitHub Security Advisory GHSA-xg26-px52-wxv6

Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 7.97%

Top 6% most likely to be exploited

Threat Score 42.4 / 100

Data Sources

NVD EPSS GitHub