Back to Database
Status published
High
CVE-2000-0727
xpdf PDF viewer client earlier than 0.91 does not properly...
Vulnerability Description
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2000-0727
Credits & Attribution
No credits recorded in the NVD database.
References
- http://marc.info/?l=bugtraq&m=96766355023239&w=2
- http://marc.info/?l=bugtraq&m=96886599829687&w=2
- http://www.debian.org/security/2000/20000910a
- http://www.securityfocus.com/bid/1624
- http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt
- http://www.redhat.com/support/errata/RHSA-2000-060.html
More from xpdf
View All →CVE-2010-0206
xpdf allows remote attackers to cause a denial of service...
Medium
5.5
CVE-2007-5393
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in...
Critical
9.3
CVE-2007-5392
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf...
Critical
9.3
CVE-2007-4352
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in...
High
7.6
CVE-2007-0104
The Adobe PDF specification 1.3, as implemented by (a) xpdf...
Medium
6.8
Affected Vendor
xpdf
View all reports →Affected Software
xpdf
Vulnerable Versions:
0.90
Timeline
Official Publish:
October 13th, 2000
Last Modified:
August 8th, 2024
Added to House:
July 17th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.