Vulnerability record · CVE-2007-0046 · published 3 January 2007
CVE-2007-0046: Adobe Acrobat Reader Plugin double free via AJAX request parameters
Adobe · Acrobat Reader
The Adobe Acrobat Reader browser plugin before 8.0.0 contains a double free vulnerability triggered through the FDF, XML, or XFDF AJAX request parameters. A remote attacker can cause an error via a javascript: URI call to document.write, leading to memory corruption. This matters because it can result in arbitrary code execution in the context of the browser.
Description
Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityCVSS 2.0 score of 7.5 and high EPSS percentile indicate significant risk, though no active exploitation in KEV is reported.
What it is
The Adobe Acrobat Reader browser plugin before 8.0.0 contains a double free vulnerability triggered through the FDF, XML, or XFDF AJAX request parameters. A remote attacker can cause an error via a javascript: URI call to document.write, leading to memory corruption. This matters because it can result in arbitrary code execution in the context of the browser.
Impact
An attacker can execute arbitrary code on the victim's system, potentially leading to full compromise of the user's machine. The CVSS 2.0 vector indicates partial confidentiality, integrity, and availability impact.
Attack surface
The flaw is reachable remotely over the network without authentication, as indicated by the CVSS vector AV:N/AC:L/Au:N. User interaction is likely required to visit a malicious page or open a crafted document, but the record does not explicitly state this.
Exploitation
The vulnerability is not listed in CISA KEV, but EPSS probability is 0.55924 (99th percentile), indicating a high likelihood of exploitation. A reference is tagged with 'Exploit', suggesting public exploit code may exist.
What to do
- Update Adobe Acrobat Reader to version 8.0.0 or later.
- Apply vendor patches referenced in Adobe security bulletin APSB07-01.
- Disable the Adobe Acrobat Reader browser plugin if not required.
- Restrict the use of javascript: URIs in browsers where possible.
- Follow vendor advisories from Red Hat, SUSE, Gentoo, and Sun for patched packages.
Detection
- Monitor for unusual document.write calls or javascript: URI invocations in browser processes.
- Detect crashes or abnormal termination of the Adobe Acrobat Reader plugin.
- Look for network requests containing FDF, XML, or XFDF parameters from untrusted sources.
- Use endpoint detection to identify memory corruption patterns in Acrobat Reader processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0046 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0046), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.