Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3459

Опубликовано: 13 окт. 2009
Источник: nvd
CVSS3: 8.8
CVSS2: 9.3
EPSS Высокий

Описание

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Версия от 7.0 (включая) до 7.1.4 (исключая)
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Версия от 8.0 (включая) до 8.1.7 (исключая)
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Версия от 9.0 (включая) до 9.2 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Версия от 7.0 (включая) до 7.1.4 (исключая)
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Версия от 8.0 (включая) до 8.1.7 (исключая)
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Версия от 9.0 (включая) до 9.2 (исключая)

EPSS

Процентиль: 100%
0.86583
Высокий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-119
CWE-122

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 17 лет назад

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

redhat
почти 17 лет назад

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

CVSS3: 8.8
github
больше 4 лет назад

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

CVSS3: 8.8
fstec
больше 17 лет назад

Уязвимость программ просмотра PDF-файлов Adobe Reader и программ редактирования PDF-файлов Adobe Acrobat, связанная с переполнением буфера в куче, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.86583
Высокий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-119
CWE-122