VDB
CVE-2008-1104
CVE-2008-1104
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Stack-based buffer overflow in Foxit Reader before 2.3 build 2912 allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file, related to the util.printf JavaScript function and floating point specifiers in format strings.
EPSS 8.72% · 92.6th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
8.72%
92.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| foxitsoftware | foxit_reader | 0, 2.0, 2.2 |
Timeline
- May 21, 2008 CVE Published
- Nov 5, 2008 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- foxitreader-utilprintf-bo(42531) vdb
- 20080520 Secunia Research: Foxit Reader "util.printf()" Buffer Overflow mailing-list
- 1020050 vdb
- VU#119747 third-party-advisory
- ADV-2008-1572 vdb
- http://secunia.com/secunia_research/2008-18/advisory/ url
- 29288 vdb
- 29941 third-party-advisory
- 3899 third-party-advisory
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=800801 url
- https://nvd.nist.gov/vuln/detail/CVE-2008-1104 advisory
- http://secunia.com/secunia_research/2008-18/advisory url