CVE heuristics

105 detection rules

← All detection heuristics

PDF JavaScript combines Acrobat prototype pollution targeting privileged state with an execution or sensitive file-read primitive.
Embedded TrueType font has malformed EBLC/EBDT bitmap-glyph placement plus the EBSC max-range table trap.
PDF JavaScript uses Acrobat internal share/login APIs, swConn prototype manipulation, and privileged RSS/file-read APIs.
Adobe Flash authplay SWF exploit in PDF — CVE-2010-1297 critical CVE_2010_1297_FLASH_RICHMEDIA
PDF combines RichMedia Flash activation, a crafted SWF with authplay-era markers, and shellcode heap-spray staging.
Adobe Flash exploit trigger — CVE-2010-1297 critical CVE_2010_1297_SWF_TRIGGER
Recovered SWF matches the public SWF9 DoABC CVE-2010-1297 newfunction trigger.
Adobe Flash exploit trigger — CVE-2011-0611 critical CVE_2011_0611_SWF_TRIGGER
Recovered SWF matches the canonical SWF10 AVM1 CVE-2011-0611 trigger.
Adobe Flash/authplay SWF exploit in PDF — CVE-2009-1862 critical CVE_2009_1862_FLASH_RICHMEDIA
PDF combines RichMedia Flash activation with a crafted Run_Sploit/HeapSpray SWF or compact AS3 SWF plus PDF-side encoded shellcode.
PDF embeds a TrueType/OpenType SING font table together with JavaScript heap-spray shellcode.
PDF has an overlong trailer /ID and JavaScript dereferences this.docID.
PDF /DecodeParms predictor parameters force an integer overflow in the per-row buffer size.
PDF embeds a malformed JPX/JPEG2000 image whose JP2 header area contains a command-execution/download payload.
Adobe Reader JPX cmap overflow trigger — CVE-2018-4990 critical CVE_2018_4990_JPX_CMAP_TRIGGER
PDF embeds the in-the-wild malformed JPEG2000 cmap construction used to trigger CVE-2018-4990.
PDF uses /Launch with shell parameters and an embedded/exported payload chain.
PDF contains XFA JavaScript that heap-sprays shellcode, builds a TIFF image payload, and assigns it to an XFA image rawValue.
PDF JavaScript reaches Android Java reflection through the Reader Mobile JavaScript bridge, obtains java.lang.Runtime, and loads an Android native/stage payload.
PDF JavaScript removes an app.addToolButton object from its cEnable callback and carries heap-spray shellcode.
PDF contains the XFA choiceList/oneOfChild trigger shape associated with CVE-2013-0640.
Adobe Reader authplay SWF exploit in PDF — CVE-2010-3654 critical CVE_2010_3654_FLASH_RICHMEDIA
PDF combines RichMedia Flash activation, AS3 DoABC/SymbolClass SWF code, and PDF-side shellcode heap-spray staging.
PDF contains a crafted mailto URI that reaches mshta via path traversal and executes inline script.
PDF matches a CVE-2014-0496-specific Adobe Reader use-after-free primitive.
HTML or PDF-embedded HTML configures C6 Messenger DownloaderActiveX to download and run a file.
OOXML external OLEObject relationship targets HTML/CAB/MSHTML-style content.
CVE 2006 4694 critical CVE_2006_4694
Static evidence associated with CVE-2006-4694.
CVE 2008 0118 critical CVE_2008_0118
Static evidence associated with CVE-2008-0118.
CVE 2009 0658 critical CVE_2009_0658
Static evidence associated with CVE-2009-0658.
CVE 2009 3953 critical CVE_2009_3953
Static evidence associated with CVE-2009-3953.
CVE 2010 1797 critical CVE_2010_1797
Static evidence associated with CVE-2010-1797.
CVE 2010 2883 Shellcode Stage critical CVE_2010_2883_SHELLCODE_STAGE
Static evidence associated with CVE-2010-2883-SHELLCODE-STAGE.
CVE 2011 2462 critical CVE_2011_2462
Static evidence associated with CVE-2011-2462.
PDF embeds a Flash SWF (RichMedia) and its de-obfuscated JavaScript heap-sprays to groom memory for the Flash exploit.
CVE-2017-0262 related DDE stager critical CVE_2017_0262_DDE_STAGER
Word DDE field downloads and executes the observed CVE-2017-0262 second-stage URL.
PDF JavaScript calls Collab.collectEmailInfo() with a long or heap-sprayed message argument.
Collab.getIcon — CVE-2009-0927 critical CVE_2009_0927
PDF JavaScript calls Collab.getIcon() with a long string argument.
Composite Moniker — CVE-2017-8570 critical CVE_2017_8570
OLE data contains the Composite Moniker CLSID with nearby scriptlet payload evidence.
Doc.printSeps — CVE-2010-4091 critical CVE_2010_4091
PDF JavaScript invokes Doc.printSeps() with exploit-shaped arguments.
Document references EPSIMP32 or contains PostScript/EPS markers.
Embedded Flash authplay SWF exploit — CVE-2010-1297 likely critical CVE_2010_1297_FLASH_EMBEDDED
PDF embeds a crafted authplay-era SWF and pairs it with PDF-side shellcode heap-spray staging.
MTEF Matrix record exploit signature found in Equation Editor OLE data.
RTF contains an activated OLE1 Equation.3 object with large payload-like native data.
Equation Editor Ole10Native payload — CVE-2017-11882 family critical CVE_2017_11882_EQUATION_OLE10NATIVE_RELATED
RTF activates a Microsoft Equation 3.0 OLE storage carrying a high-entropy Ole10Native payload.
MTEF SIZE record contains an exploit-sized explicit point size or delta.
Equation Editor command stager — CVE-2017-11882 family critical CVE_2017_11882_COMMAND_STAGER_RELATED
Activated Equation Editor object carries command-launch bytes without a recoverable individual-CVE MTEF primitive.
Excel's shared-string index table (EXTSST) declares far more entries than the workbook's string count allows — the CVE-2011-0105 memory-corruption shape.
Excel FEATHEADER record declares an oversized/inconsistent internal length — the CVE-2009-3129 parser-overflow shape (legitimate records are only tens of bytes).
Excel HTML/XML workbook markup contains unexpected nested content in x:WorksheetOptions.
Legacy Excel BIFF8 workbook combines a narrow FORMAT-index cluster with large OLE slack payload staging.
Excel workbook has repeated malformed drawing-object (OBJ) records using an invalid target value, alongside shellcode/heap-spray context — the CVE-2009-0238 shape.
Excel workbook combines abnormal Forms.CommandButton OBJ record IDs with XLM/VBA auto-execution context.
Follina/MSDT URI — CVE-2022-30190 critical CVE_2022_30190
Document contains an ms-msdt: URI consistent with Follina payload delivery.
PDF JavaScript matches the public Foxit Reader 9.0.1.1049 annotation-UAF exploitation chain.
Embedded PostScript/EPS uses Ghostscript CVE-2017-8291 exploitation primitives.
Embedded HWP EPS/PostScript matches the CVE-2013-0808 exploit staging shape.
HWPX BinData embeds a malformed prefixed OLE/CFB chart object with shellcode-style API markers.
Malformed Word ActiveX package — CVE-2017-11826 critical CVE_2017_11826_ACTIVEX_PACKAGE
RTF embeds a Word.Document.12 package with repeated null-CLSID ActiveX controls and an oversized activeX1.bin CFB payload.
Moniker Link — CVE-2024-21413 critical CVE_2024_21413
Document contains a file:///\\ moniker-link target with an exclamation mark.
Document contains Shell.Explorer.1 CLSID evidence plus OLE activation context.
RTF OLE2Link object is force-activated with \objupdate and fetches a remote second stage via an INCLUDE field.
Office document embeds EPS/PostScript with exploit-style dynamic execution or decode-filter markers.
Outlook .msg contains UNC reminder evidence: exact for ReminderFileParameter, related for raw UNC fallback.
Document XML/HTML contains an <img> tag with file://...!... moniker URL.
PDF font dictionary contains non-numeric FontMatrix values.
PowerPoint 95 native file has inconsistent PP7 directory lengths, sound-data marker, and nearby native payload bytes.
Binary PowerPoint stream contains an embedded .inf object reference with package data.
PowerPoint Document contains a malformed EscherClientTextbox with TextHeaderAtom, repeated-byte TextBytesAtom payload, and OutlineTextRefAtom.
RTF Word ActiveX package — CVE-2015-1641 related critical CVE_2015_1641_ACTIVEX_RELATED
RTF objdata embeds Word.Document.12 packages with many repeated ActiveX controls and oversized activeX1.bin.
RTF Word ActiveX package — CVE-2015-1770 related critical CVE_2015_1770_ACTIVEX_RELATED
RTF objdata embeds Word.Document.12 packages with many repeated ActiveX controls and oversized activeX1.bin.
SOAP Moniker — CVE-2017-8759 critical CVE_2017_8759
OLE data contains the SOAP Moniker CLSID.
OLE Package CLSID found alongside executable file references.
OOXML .rels file contains an auto-load relationship Target pointing to a remote .rtf URL.
Decrypted Type 1 CharString matches the public callOtherSubr stack-pointer manipulation shape.
URL Moniker weaponized URL — CVE-2017-0199 critical CVE_2017_0199_WEAPONIZED_URL
URL Moniker OLE link points to an HTA/script/template-style remote loader.
URL Moniker — CVE-2017-0199 critical CVE_2017_0199
URL Moniker OLE link points to a remote loader.
UTF-16BE Base URL — CVE-2021-39863 critical CVE_2021_39863
PDF catalog uses a UTF-16BE /URI /Base value and JavaScript resolves a relative URL.
Decoded PDF shellcode invokes the NDProxy TAPI IOCTL 0x8fff23c8 with null-page kernel-stub setup.
Word/OLE data contains the MS15-022 local-zone exploit chain.
Word 97-era document places shellcode immediately before a malformed converter-facing table-SPRM cluster.
RTF font table with excessive entries — Word heap buffer overflow.
RTF contains an oversized pFragments value.
customUI ribbon part contains an external relationship target.
PDF embeds a file and JavaScript triggers the dataObjects ESObject use-after-free pattern.
media.newPlayer — CVE-2009-4324 critical CVE_2009_4324
PDF JavaScript calls the media.newPlayer API.
util.printf — CVE-2008-2992 critical CVE_2008_2992
PDF JavaScript invokes util.printf() with an oversized format/string argument.
ADODB.RecordSet — CVE-2015-0097 related high CVE_2015_0097_RELATED
OLE data contains the ADODB.RecordSet CLSID.
Anomalous Equation Editor native stream — CVE-2018-0798 likely high CVE_2018_0798_EQUATION_NATIVE_ANOMALY
Embedded Equation Editor OLE data contains malformed, payload-like native stream bytes.
CVE-2012-0158 RTF embedded encrypted payload high RTF_CVE_2012_0158_EMBEDDED_PAYLOAD
A CVE-2012-0158 RTF carries a large high-entropy binary blob — the encrypted/packed second-stage payload the shellcode drops.
CoolType/SING font exploit indicator high PDF_COOLTYPE_SING
PDF font data contains SING/CoolType markers inside font content.
Equation Editor activation — CVE-2017-11882 related high CVE_2017_11882_ACTIVATION_RELATED
RTF decodes to Equation.3 object activation without a recovered malformed native stream.
Raw email From header contains multiple parsed/angle-bracket addresses.
GoToE/GoToR UNC action — CVE-2018-4993 high CVE_2018_4993_GOTOE_UNC
PDF automatic/open action uses GoToE or GoToR with a UNC /F target.
JBIG2 + active content high PDF_JBIG2_ACTIVE_CONTENT
PDF uses JBIG2Decode/JBIG2 data alongside active content.
OLE data contains the MSCOMCTL.ListView CLSID.
OLE data contains the MSCOMCTL.Toolbar CLSID.
MSScriptControl — CVE-2015-0097 high CVE_2015_0097_SC
OLE data contains the MSScriptControl.ScriptControl CLSID.
Malformed JPEG2000/JP2 box structure high PDF_JP2_BOX_ANOMALY
Embedded JP2/JPEG2000 data has invalid, oversized, or truncated box sizes.
OOXML OLE2Link object fetches a remote Office-looking document.
OOXML linked OLE object auto-loads a remote URL without enough local evidence for an exact CVE.
Equation Editor MTEF Matrix record has an anomalous exploit-like shape.
Suspicious JBIG2 segment structure high PDF_JBIG2_SEGMENT_ANOMALY
Embedded JBIG2 data contains anomalous segment headers or sizes.
PDF action target contains a UNC path and the file has action triggers.
Document contains CVE-2026-21514-style Word/OLE bypass indicators.
RTF \listoverridecount with abnormally large value.
getAnnots — CVE-2009-1492 high CVE_2009_1492
PDF JavaScript calls getAnnots() with an exploit-shaped argument.
PDF JavaScript invokes spell.customDictionaryOpen() with a long string argument.
PRC/3D content in PDF low PDF_PRC_3D
PDF contains PRC 3D content markers.
PDF font marker lacks validated CVE exploit shape info PDF_FONT_CVE_NOT_VALIDATED
PDF font data has SING/CoolType markers without the stricter validated CVE exploit shape.