VDB
CVE-2003-0434
CVE-2003-0434
PUBLISHED
CVSS 7.5 HIGH
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
EPSS 25.51% · 96.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
25.51%
96.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mandrakesoft | mandrake_linux | 9.0, 9.1 |
| xpdf | xpdf | 1.1 |
| redhat | linux_advanced_workstation | 2.1 |
| n/a | n/a | * |
| adobe | acrobat | 5.0.6 |
| redhat | enterprise_linux | 2.1, 2.1, 2.1 |
| mandrakesoft | mandrake_linux_corporate_server | 2.1 |
| redhat | linux | 9.0, 8.0, 7.3 |
Timeline
- Jun 18, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 3, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- 9038 third-party-advisory
- MDKSA-2003:071 vendor-advisory
- VU#200132 third-party-advisory
- 20030613 -10Day CERT Advisory on PDF Files mailing-list
- RHSA-2003:196 vendor-advisory
- 9037 third-party-advisory
- RHSA-2003:197 vendor-advisory
- 20030709 xpdf vulnerability - CAN-2003-0434 mailing-list
- oval:org.mitre.oval:def:664 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2003-0434 advisory