CVE-2008-4817

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
05/11/2008
Last modified:
09/04/2025

Description

The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:download_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:*:unknown:3d:*:*:*:*:* 8.1.2 (including)
cpe:2.3:a:adobe:acrobat:*:unknown:professional:*:*:*:*:* 8.1.2 (including)
cpe:2.3:a:adobe:acrobat:*:unknown:standard:*:*:*:*:* 8.1.2 (including)
cpe:2.3:a:adobe:acrobat:8.1.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:8.1.1:unknown:3d:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:8.1.1:unknown:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:8.1.1:unknown:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* 8.0 (including)