Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-1492

Опубликовано: 30 апр. 2009
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Версия от 7.0 (включая) до 7.1.1 (включая)
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Версия от 8.0 (включая) до 8.1.4 (включая)
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Версия от 9.0 (включая) до 9.1 (включая)
Конфигурация 2

Одно из

cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Версия от 7.0 (включая) до 7.1.1 (включая)
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Версия от 8.0 (включая) до 8.1.4 (включая)
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Версия от 9.0 (включая) до 9.1 (включая)

EPSS

Процентиль: 99%
0.68063
Средний

9.3 Critical

CVSS2

Дефекты

CWE-399

Связанные уязвимости

ubuntu
почти 17 лет назад

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

redhat
почти 17 лет назад

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

github
почти 4 года назад

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

EPSS

Процентиль: 99%
0.68063
Средний

9.3 Critical

CVSS2

Дефекты

CWE-399