CVE-2004-0631

CRITICAL

Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute a...

Affects 1 product across 1 vendor.

BCS7.9
CVSS 2.010.0
EPSS9.8%
Percentile95th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2004. A critical vulnerability affects Adobe systems (CVE-2004-0631). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2004-GLOBAL-008020-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2004-0631?
This vulnerability was disclosed in 2004. A critical vulnerability affects Adobe systems (CVE-2004-0631). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2004-0631?
CVE-2004-0631 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 9.8%.
Is CVE-2004-0631 actively exploited?
No confirmed active exploitation of CVE-2004-0631 as of 2026-05-30.
How do I remediate CVE-2004-0631?
Priority: MEDIUM. Advisory: http://security.gentoo.org/glsa/glsa-200408-14.xml PSIRT: [email protected]
What systems are affected by CVE-2004-0631?
CVE-2004-0631 affects: Adobe.
Vulnerability Details
CVE IDCVE-2004-0631
BSIDBS-2004-GLOBAL-008020-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2004-08-18
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the uudecode command.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the uudecode command. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Adobe Acrobat Reader
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 8019 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashca84d83924dd2d2dce2d70ac8e351103e909b0d3b5b02fe94eb212dfabfde329dc912a5a3181e6aef9b2c6b467bb9d69445b9e7531debde8a24c0ebbf2511764
Related CVEs affecting Adobe
CVE-2015-5101 10.0 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.15 ... CVE-2015-6691 10.0 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 ... CVE-2004-1152 10.0 Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 fo... CVE-2004-1153 10.0 Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allow... CVE-2015-8407 10.0 Stack-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x ...
View all Adobe CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →