Back
CVE-2004-1153
Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.
Published: Jan 10, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| adobe | acrobat_reader | 6.0 |
| adobe | acrobat_reader | 6.0.2 |
| adobe | acrobat_reader | 8.0 |
GitHub Security Advisory GHSA-xg26-px52-wxv6
Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers...
References (8)
- http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679
- http://www.idefense.com/application/poi/display?id=163&type=vulnerabilities Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18478
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2919
- http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679
- http://www.idefense.com/application/poi/display?id=163&type=vulnerabilities Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18478
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2919
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
7.97%
Top 6% most likely to be exploited
Threat Score
42.4 / 100
Data Sources
NVD
EPSS
GitHub