CVE-2009-3958
high · 10Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.
10
CVSS
52.6%
EPSS (exploit prob.)
99th
EPSS percentile
2010-01-13
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | acrobat | <= 9.2 |
| adobe | acrobat | 3.0 |
| adobe | acrobat | 3.1 |
| adobe | acrobat | 4.0 |
| adobe | acrobat | 4.0.5 |
| adobe | acrobat | 4.0.5a |
| adobe | acrobat | 4.0.5c |
| adobe | acrobat | 5.0 |
| adobe | acrobat | 5.0.5 |
| adobe | acrobat | 5.0.6 |
| adobe | acrobat | 5.0.10 |
| adobe | acrobat | 6.0 |
| adobe | acrobat | 6.0.1 |
| adobe | acrobat | 6.0.2 |
| adobe | acrobat | 6.0.3 |
| adobe | acrobat | 6.0.4 |
| adobe | acrobat | 6.0.5 |
| adobe | acrobat | 6.0.6 |
| adobe | acrobat | 7.0 |
| adobe | acrobat | 7.0.1 |
| adobe | acrobat | 7.0.2 |
| adobe | acrobat | 7.0.3 |
| adobe | acrobat | 7.0.4 |
| adobe | acrobat | 7.0.5 |
| adobe | acrobat | 7.0.6 |
| adobe | acrobat | 7.0.7 |
| adobe | acrobat | 7.0.8 |
| adobe | acrobat | 7.0.9 |
| adobe | acrobat | 7.1.0 |
| adobe | acrobat | 7.1.1 |
| adobe | acrobat | 7.1.2 |
| adobe | acrobat | 7.1.3 |
| adobe | acrobat | 7.1.4 |
| adobe | acrobat | 8.0 |
| adobe | acrobat | 8.1 |
| adobe | acrobat | 8.1.1 |
| adobe | acrobat | 8.1.2 |
| adobe | acrobat | 8.1.3 |
| adobe | acrobat | 8.1.4 |
| adobe | acrobat | 8.1.5 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://www.adobe.com/support/security/bulletins/apsb10-02.html
- http://www.kb.cert.org/vuls/id/773545
- http://www.securityfocus.com/bid/37759
- http://www.securitytracker.com/id?1023446
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html
- http://www.vupen.com/english/advisories/2010/0103
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55556
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8455
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://www.adobe.com/support/security/bulletins/apsb10-02.html
- http://www.kb.cert.org/vuls/id/773545
- http://www.securityfocus.com/bid/37759
- http://www.securitytracker.com/id?1023446
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html
- http://www.vupen.com/english/advisories/2010/0103
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55556
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8455
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-3958