« Volver al listado

CVE-2012-4337

Estado: ModificadaAlta (9.3)—

Foxit Reader before 5.3 on Windows XP and Windows 7 allows remote attackers to execute arbitrary code via a PDF document with a crafted attachment that triggers calculation of a negative number during processing of cross references.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-4337",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-23T15:55:00.937",
  "references": [
    {
      "url": "http://secunia.com/advisories/50359",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1027424",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://technet.microsoft.com/security/msvr/msvr12-013",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.foxitsoftware.com/Secure_PDF_Reader/security_bulletins.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/84808",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/55150",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/50359",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1027424",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://technet.microsoft.com/security/msvr/msvr12-013",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.foxitsoftware.com/Secure_PDF_Reader/security_bulletins.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/84808",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/55150",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Foxit Reader before 5.3 on Windows XP and Windows 7 allows remote attackers to execute arbitrary code via a PDF document with a crafted attachment that triggers calculation of a negative number during processing of cross references."
    },
    {
      "lang": "es",
      "value": "Foxit Reader anterior a v5.3 en Windows XP y Windows 7 permite a atacantes remotos ejecutar código arbitrario a través de un documento PDF con un adjunto manipulado que provoca el cálculo de un número negativo durante el procesamiento de referencias cruzadas."
    }
  ],
  "lastModified": "2026-06-16T23:44:51.057",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF60713D-4E53-4F3D-93F0-1FAD6BEEB87E",
              "versionEndIncluding": "5.1.4.0104"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42134F7D-ED60-4815-BADD-542BBEFE7A2B"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C133A953-B2F9-4168-8E00-91254ADC5C0D"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30CB7169-357B-42FB-B680-044883A8D9D5"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:3.1.2.1013:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECEB0F41-DE65-458C-AB84-4F4077068AD6"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:3.1.2.1030:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76331C11-BCD2-4B38-B3BF-1B0E1DD2668C"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:3.2.0.0303:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7F49C93-DF54-4423-9561-08C2A05D87CF"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:3.2.1.0401:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0266A97-F74D-4095-9535-283467CBADD9"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A870E65C-F3F3-4F1F-BE9C-B22AF850A804"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:4.0.0.0619:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B71EF882-62FF-4B2E-A051-AD57573F82DA"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1630FBB-1C9A-4FC5-992A-37B10374F21C"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:4.1.1.0805:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CA7306B-0C89-42F4-850A-457EFD7AC3A1"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23ADE7D6-EF82-469A-961E-A76DDB53646C"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:4.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC34C9CD-B0E3-49DD-B6D8-28099A89F7DE"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:4.3.1.0218:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "813F1E20-693C-4166-884D-A570AA6D111E"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F240F6F7-E169-4BFC-930D-60F5B6D87A90"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:5.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDA32097-473E-48DD-874B-75E572110204"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:5.1.0.1021:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0441623-09EB-41D6-9548-AD699D5EFB68"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_reader:5.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F6B7FF9-4AE5-4694-BE2F-288B56AE2FDE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D56B932B-9593-44E2-B610-E4EB2143EB21"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E61F1C9B-44AF-4B35-A7B2-948EEF7639BD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}