Page 56 of 276 results (0.003 seconds)

CVSS: 9.3EPSS: 2%CPEs: 7EXPL: 3

Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action" sequence, a related issue to CVE-2009-0836. Foxit Reader anterior a v3.2.1.0401 permite a atacantes remotos (1) ejecutar programas locales de su elección a través de determinadas secuencias "/Type /Action /S /Launch" y (2) ejecutar programas de su elección embebidos en un documento PDF a través de secuencias "/Launch /Action" no especificadas. Relacionado con el CVE-2009-0836. • https://www.exploit-db.com/exploits/11987 http://blog.didierstevens.com/2010/03/29/escape-from-pdf http://blog.didierstevens.com/2010/03/31/escape-from-foxit-reader http://www.f-secure.com/weblog/archives/00001923.html http://www.foxitsoftware.com/announcements/2010420408.html http://www.foxitsoftware.com/pdf/reader/security.htm#0401 http://www.kb.cert.org/vuls/id/570177 • CWE-94: Improper Control of Generation of Code ('Code Injection') •