CVE-2009-3959
Summary
| CVE | CVE-2009-3959 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-01-13 19:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a malformed PDF document. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Acrobat | 3.0 | All | All | All |
| Application | Adobe | Acrobat | 3.1 | All | All | All |
| Application | Adobe | Acrobat | 4.0 | All | All | All |
| Application | Adobe | Acrobat | 4.0.5 | All | All | All |
| Application | Adobe | Acrobat | 4.0.5a | All | All | All |
| Application | Adobe | Acrobat | 4.0.5c | All | All | All |
| Application | Adobe | Acrobat | 5.0 | All | All | All |
| Application | Adobe | Acrobat | 5.0.10 | All | All | All |
| Application | Adobe | Acrobat | 5.0.5 | All | All | All |
| Application | Adobe | Acrobat | 5.0.6 | All | All | All |
| Application | Adobe | Acrobat | 6.0 | All | All | All |
| Application | Adobe | Acrobat | 6.0.1 | All | All | All |
| Application | Adobe | Acrobat | 6.0.2 | All | All | All |
| Application | Adobe | Acrobat | 6.0.3 | All | All | All |
| Application | Adobe | Acrobat | 6.0.4 | All | All | All |
| Application | Adobe | Acrobat | 6.0.5 | All | All | All |
| Application | Adobe | Acrobat | 6.0.6 | All | All | All |
| Application | Adobe | Acrobat | 7.0 | All | All | All |
| Application | Adobe | Acrobat | 7.0.1 | All | All | All |
| Application | Adobe | Acrobat | 7.0.2 | All | All | All |
| Application | Adobe | Acrobat | 7.0.3 | All | All | All |
| Application | Adobe | Acrobat | 7.0.4 | All | All | All |
| Application | Adobe | Acrobat | 7.0.5 | All | All | All |
| Application | Adobe | Acrobat | 7.0.6 | All | All | All |
| Application | Adobe | Acrobat | 7.0.7 | All | All | All |
| Application | Adobe | Acrobat | 7.0.8 | All | All | All |
| Application | Adobe | Acrobat | 7.0.9 | All | All | All |
| Application | Adobe | Acrobat | 7.1.0 | All | All | All |
| Application | Adobe | Acrobat | 7.1.1 | All | All | All |
| Application | Adobe | Acrobat | 7.1.2 | All | All | All |
| Application | Adobe | Acrobat | 7.1.3 | All | All | All |
| Application | Adobe | Acrobat | 7.1.4 | All | All | All |
| Application | Adobe | Acrobat | 8.0 | All | All | All |
| Application | Adobe | Acrobat | 8.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat | 8.1.3 | All | All | All |
| Application | Adobe | Acrobat | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat | 8.1.5 | All | All | All |
| Application | Adobe | Acrobat | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat | 8.1.7 | All | All | All |
| Application | Adobe | Acrobat | 9.0 | All | All | All |
| Application | Adobe | Acrobat | 9.1 | All | All | All |
| Application | Adobe | Acrobat | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat | 9.1.3 | All | All | All |
| Application | Adobe | Acrobat | All | All | All | All |
| Application | Adobe | Acrobat Reader | 3.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 3.01 | All | All | All |
| Application | Adobe | Acrobat Reader | 3.02 | All | All | All |
| Application | Adobe | Acrobat Reader | 4.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 4.0.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 4.0.5a | All | All | All |
| Application | Adobe | Acrobat Reader | 4.0.5c | All | All | All |
| Application | Adobe | Acrobat Reader | 4.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 5.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 5.0.10 | All | All | All |
| Application | Adobe | Acrobat Reader | 5.0.11 | All | All | All |
| Application | Adobe | Acrobat Reader | 5.0.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 5.0.6 | All | All | All |
| Application | Adobe | Acrobat Reader | 5.0.7 | All | All | All |
| Application | Adobe | Acrobat Reader | 5.0.9 | All | All | All |
| Application | Adobe | Acrobat Reader | 5.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 6.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 6.0.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 6.0.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 6.0.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 6.0.4 | All | All | All |
| Application | Adobe | Acrobat Reader | 6.0.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.4 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.6 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.7 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.8 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.9 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.7 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.3 | All | All | All |
| Application | Adobe | Acrobat Reader | All | All | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Red Hat update for acroread - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Adobe Acrobat and Adobe Reader Flaws Lets Remote Users Execute Arbitrary Code and Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Adobe - Security Bulletin APSB10-02 Security updates available for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Adobe Reader/Acrobat 7 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [security-announce] SUSE Security Announcement: acoread (SUSE-SA:2010:00 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| US-CERT Technical Cyber Security Alert TA10-013A -- Adobe Reader and Acrobat Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Adobe Reader and Acrobat U3D Support Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Bug 554293 – CVE-2009-3953 CVE-2009-3954 CVE-2009-3955 CVE-2009-3959 acroread: multiple code execution flaws (APSB10-02) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.