9.3
CVE-2009-1492
- EPSS 66.96%
- Published 30.04.2009 20:30:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.
Data is provided by the National Vulnerability Database (NVD)
Adobe ≫ Acrobat Reader Version >= 7.0 <= 7.1.1
Adobe ≫ Acrobat Reader Version >= 8.0 <= 8.1.4
Adobe ≫ Acrobat Reader Version >= 9.0 <= 9.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 66.96% | 0.984 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|