9.3

CVE-2009-1492

Exploit

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

Data is provided by the National Vulnerability Database (NVD)
AdobeAcrobat Version >= 7.0 <= 7.1.1
AdobeAcrobat Version >= 8.0 <= 8.1.4
AdobeAcrobat Version >= 9.0 <= 9.1
AdobeAcrobat Reader Version >= 7.0 <= 7.1.1
AdobeAcrobat Reader Version >= 8.0 <= 8.1.4
AdobeAcrobat Reader Version >= 9.0 <= 9.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 66.96% 0.984
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
http://www.kb.cert.org/vuls/id/970180
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/34736
Third Party Advisory
Exploit
VDB Entry
http://www.securitytracker.com/id?1022139
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA09-133B.html
Third Party Advisory
US Government Resource
https://www.exploit-db.com/exploits/8569
Third Party Advisory
VDB Entry