Lucene search

K
cveMitreCVE-2009-1492
HistoryApr 30, 2009 - 8:30 p.m.

CVE-2009-1492

2009-04-3020:30:00
CWE-399
mitre
web.nvd.nist.gov
50
cve-2009-1492
adobe reader
acrobat
javascript api
denial of service
memory corruption
arbitrary code
remote attackers
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0.962

Percentile

99.5%

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

Affected configurations

Nvd
Node
adobeacrobatRange7.07.1.1
OR
adobeacrobatRange8.08.1.4
OR
adobeacrobatRange9.09.1
Node
adobeacrobat_readerRange7.07.1.1
OR
adobeacrobat_readerRange8.08.1.4
OR
adobeacrobat_readerRange9.09.1
VendorProductVersionCPE
adobeacrobat*cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
adobeacrobat_reader*cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0.962

Percentile

99.5%