CVE-2011-0604: XSS
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0587.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0604?
CVE-2011-0604 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2011-0604?
To fix CVE-2011-0604, update Adobe Reader and Acrobat to version 10.0.1 or later, 9.4.2 or later, or 8.2.6 or later.
What products are affected by CVE-2011-0604?
CVE-2011-0604 affects Adobe Reader and Acrobat versions 8.x before 8.2.6, 9.x before 9.4.2, and 10.x before 10.0.1.
Can CVE-2011-0604 be exploited remotely?
Yes, CVE-2011-0604 can be exploited remotely, allowing attackers to inject arbitrary web scripts or HTML.
Is there a risk of data theft with CVE-2011-0604?
Yes, due to the nature of XSS vulnerabilities, CVE-2011-0604 poses a risk of data theft and unauthorized actions on behalf of users.