
<A HREF="http://www.eweek.com/article2/0,1895,2079201,00.asp?kc=EWEWEMNL010107EP26A">Serious security vulnerabilities</A> in two desktop applications could allow malicious hackers to plant malicious code on millions of computers, according to warnings from the U.S. government's computer emergency response team. The more serious of the two is a cross-site scripting bug in Adobe's ever-present Acrobat Plug-In, which fails to properly validate user-supplied data. The issue, which has been patched in Adobe Reader 8 can leverage any Web site that hosts a PDF file to launch code execution or denial-of-service attacks.