CVE-2009-3959
high · 10Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a malformed PDF document.
10
CVSS
11.5%
EPSS (exploit prob.)
96th
EPSS percentile
2010-01-13
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-189
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | acrobat | <= 9.2 |
| adobe | acrobat | 3.0 |
| adobe | acrobat | 3.1 |
| adobe | acrobat | 4.0 |
| adobe | acrobat | 4.0.5 |
| adobe | acrobat | 4.0.5a |
| adobe | acrobat | 4.0.5c |
| adobe | acrobat | 5.0 |
| adobe | acrobat | 5.0.5 |
| adobe | acrobat | 5.0.6 |
| adobe | acrobat | 5.0.10 |
| adobe | acrobat | 6.0 |
| adobe | acrobat | 6.0.1 |
| adobe | acrobat | 6.0.2 |
| adobe | acrobat | 6.0.3 |
| adobe | acrobat | 6.0.4 |
| adobe | acrobat | 6.0.5 |
| adobe | acrobat | 6.0.6 |
| adobe | acrobat | 7.0 |
| adobe | acrobat | 7.0.1 |
| adobe | acrobat | 7.0.2 |
| adobe | acrobat | 7.0.3 |
| adobe | acrobat | 7.0.4 |
| adobe | acrobat | 7.0.5 |
| adobe | acrobat | 7.0.6 |
| adobe | acrobat | 7.0.7 |
| adobe | acrobat | 7.0.8 |
| adobe | acrobat | 7.0.9 |
| adobe | acrobat | 7.1.0 |
| adobe | acrobat | 7.1.1 |
| adobe | acrobat | 7.1.2 |
| adobe | acrobat | 7.1.3 |
| adobe | acrobat | 7.1.4 |
| adobe | acrobat | 8.0 |
| adobe | acrobat | 8.1 |
| adobe | acrobat | 8.1.1 |
| adobe | acrobat | 8.1.2 |
| adobe | acrobat | 8.1.3 |
| adobe | acrobat | 8.1.4 |
| adobe | acrobat | 8.1.5 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://secunia.com/advisories/38138
- http://secunia.com/advisories/38215
- http://www.adobe.com/support/security/bulletins/apsb10-02.html
- http://www.redhat.com/support/errata/RHSA-2010-0060.html
- http://www.securityfocus.com/archive/1/508949
- http://www.securityfocus.com/bid/37756
- http://www.securitytracker.com/id?1023446
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html
- http://www.vupen.com/english/advisories/2010/0103
- https://bugzilla.redhat.com/show_bug.cgi?id=554293
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55557
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8539
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://secunia.com/advisories/38138
- http://secunia.com/advisories/38215
- http://www.adobe.com/support/security/bulletins/apsb10-02.html
- http://www.redhat.com/support/errata/RHSA-2010-0060.html
- http://www.securityfocus.com/archive/1/508949
- http://www.securityfocus.com/bid/37756
- http://www.securitytracker.com/id?1023446
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html
- http://www.vupen.com/english/advisories/2010/0103
- https://bugzilla.redhat.com/show_bug.cgi?id=554293
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55557
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-3959