CVE-2009-3459

HIGH

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

CVSS v3.1 Score

8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Complexity
LOW
Privileges
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Published: 10/13/2009Modified: 5/21/2026

Related Intelligence (0)

No articles currently reference this CVE.

References (25)

http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.htmlVendor AdvisoryBroken Linkhttp://isc.sans.org/diary.html?storyid=7300Not Applicablehttp://secunia.com/advisories/36983Vendor Advisoryhttp://securitytracker.com/id?1023007Broken Linkhttp://www.adobe.com/support/security/bulletins/apsb09-15.htmlPatchVendor Advisoryhttp://www.iss.net/threats/348.htmlBroken Linkhttp://www.securityfocus.com/bid/36600Broken Linkhttp://www.us-cert.gov/cas/techalerts/TA09-286B.htmlUS Government Resourcehttp://www.vupen.com/english/advisories/2009/2851Vendor Advisoryhttp://www.vupen.com/english/advisories/2009/2898Vendor Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/53691Third Party AdvisoryVDB Entryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6534Broken Linkhttp://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.htmlVendor AdvisoryBroken Linkhttp://isc.sans.org/diary.html?storyid=7300Not Applicablehttp://secunia.com/advisories/36983Vendor Advisoryhttp://securitytracker.com/id?1023007Broken Linkhttp://www.adobe.com/support/security/bulletins/apsb09-15.htmlPatchVendor Advisoryhttp://www.iss.net/threats/348.htmlBroken Linkhttp://www.securityfocus.com/bid/36600Broken Linkhttp://www.us-cert.gov/cas/techalerts/TA09-286B.htmlUS Government Resourcehttp://www.vupen.com/english/advisories/2009/2851Vendor Advisoryhttp://www.vupen.com/english/advisories/2009/2898Vendor Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/53691Third Party AdvisoryVDB Entryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6534Broken Linkhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3459US Government Resource