CVE-2009-1492
Published Apr 30, 2009
Last updated 6 years ago
Overview
- Description
- The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-399
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C45837B4-F4F9-45DC-B324-48BD4AB51973", "versionEndIncluding": "7.1.1", "versionStartIncluding": "7.0" }, { "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C1BEE55-AAE2-4D61-9156-7E34692469C1", "versionEndIncluding": "8.1.4", "versionStartIncluding": "8.0" }, { "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "746FE43A-5FB1-4EF1-8004-E5183BAB51B7", "versionEndIncluding": "9.1", "versionStartIncluding": "9.0" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4BB02266-8184-4A96-A1F0-66C9A3F0A329", "versionEndIncluding": "7.1.1", "versionStartIncluding": "7.0" }, { "criteria": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "07DD4484-A823-4B8B-8939-44A553E2FD63", "versionEndIncluding": "8.1.4", "versionStartIncluding": "8.0" }, { "criteria": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0740542B-CD65-4CE7-AA8C-43D252D66498", "versionEndIncluding": "9.1", "versionStartIncluding": "9.0" } ], "operator": "OR" } ] } ]