9.3

CVE-2009-0658

Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.

Data is provided by the National Vulnerability Database (NVD)
AdobeAcrobat Version >= 7.0 <= 7.1.1
AdobeAcrobat Version >= 8.0 <= 8.1.4
AdobeAcrobat Version9.0
AdobeAcrobat Reader Version >= 7.0 <= 7.1.1
AdobeAcrobat Reader Version >= 8.0 <= 8.1.4
AdobeAcrobat Reader Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 90.8% 0.996
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.kb.cert.org/vuls/id/905281
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/33751
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1021739
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA09-051A.html
Third Party Advisory
US Government Resource
https://www.exploit-db.com/exploits/8090
Third Party Advisory
VDB Entry
https://www.exploit-db.com/exploits/8099
Third Party Advisory
VDB Entry