{"api_version":"1","generated_at":"2026-07-23T08:58:05+00:00","cve":"CVE-2009-3953","urls":{"html":"https://cve.report/CVE-2009-3953","api":"https://cve.report/api/cve/CVE-2009-3953.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3953","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3953"},"summary":{"title":"CVE-2009-3953","description":"The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration \"array boundary issue,\" a different vulnerability than CVE-2009-2994.","state":"PUBLISHED","assigner":"adobe","published_at":"2010-01-13 19:30:00","updated_at":"2026-04-21 21:12:20"},"problem_types":["CWE-787","n/a","CWE-787 CWE-787 Out-of-bounds Write"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2010/0103","name":"http://www.vupen.com/english/advisories/2010/0103","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38215","name":"http://secunia.com/advisories/38215","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Red Hat update for acroread - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3953","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3953","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/37758","name":"http://www.securityfocus.com/bid/37758","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Adobe Reader and Acrobat U3D Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1023446","name":"http://www.securitytracker.com/id?1023446","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Adobe Acrobat and Adobe Reader Flaws Lets Remote Users Execute Arbitrary Code and Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/bulletins/apsb10-02.html","name":"http://www.adobe.com/support/security/bulletins/apsb10-02.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable","Patch","Vendor Advisory"],"title":"Adobe - Security Bulletin APSB10-02 Security updates available for Adobe Reader and Acrobat","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0060.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0060.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55551","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55551","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38138","name":"http://secunia.com/advisories/38138","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Adobe Reader/Acrobat 7 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Announcement: acoread (SUSE-SA:2010:00","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/61690","name":"http://osvdb.org/61690","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html","name":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA10-013A -- Adobe Reader and Acrobat Vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=554293","name":"https://bugzilla.redhat.com/show_bug.cgi?id=554293","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"Bug 554293 – CVE-2009-3953 CVE-2009-3954 CVE-2009-3955 CVE-2009-3959 acroread: multiple code execution flaws (APSB10-02)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl","name":"http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"The Metasploit Framework - Module Browser","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3953","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3953","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[{"source":"ADP","time":"2022-06-08T00:00:00.000Z","lang":"en","value":"CVE-2009-3953 added to CISA KEV"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3953","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2009","cve_id":"3953","cve":"CVE-2009-3953","vendorProject":"Adobe","product":"Acrobat and Reader","vulnerabilityName":"Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability","dateAdded":"2022-06-08","shortDescription":"Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-06-22","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2009-3953","cwes":"CWE-119","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:15"},"epss":{"cve_year":"2009","cve_id":"3953","cve":"CVE-2009-3953","epss":"0.838550000","percentile":"0.996630000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:45:50.938Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl"},{"name":"38138","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38138"},{"name":"oval:org.mitre.oval:def:8242","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb10-02.html"},{"name":"RHSA-2010:0060","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0060.html"},{"name":"ADV-2010-0103","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0103"},{"name":"1023446","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023446"},{"name":"61690","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/61690"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=554293"},{"name":"acrobat-reader-u3d-code-execution(55551)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55551"},{"name":"38215","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38215"},{"name":"SUSE-SA:2010:008","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html"},{"name":"TA10-013A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html"},{"name":"37758","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/37758"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2009-3953","options":[{"Exploitation":"active"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-02-04T21:43:54.138266Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2022-06-08","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3953"},"type":"kev"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-787","description":"CWE-787 Out-of-bounds Write","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-22T00:05:53.712Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3953"}],"timeline":[{"lang":"en","time":"2022-06-08T00:00:00.000Z","value":"CVE-2009-3953 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-01-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration \"array boundary issue,\" a different vulnerability than CVE-2009-2994."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"078d4453-3bcd-4900-85e6-15281da43538","shortName":"adobe"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl"},{"name":"38138","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38138"},{"name":"oval:org.mitre.oval:def:8242","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb10-02.html"},{"name":"RHSA-2010:0060","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0060.html"},{"name":"ADV-2010-0103","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0103"},{"name":"1023446","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023446"},{"name":"61690","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/61690"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=554293"},{"name":"acrobat-reader-u3d-code-execution(55551)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55551"},{"name":"38215","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38215"},{"name":"SUSE-SA:2010:008","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html"},{"name":"TA10-013A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html"},{"name":"37758","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/37758"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@adobe.com","ID":"CVE-2009-3953","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration \"array boundary issue,\" a different vulnerability than CVE-2009-2994."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl","refsource":"MISC","url":"http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl"},{"name":"38138","refsource":"SECUNIA","url":"http://secunia.com/advisories/38138"},{"name":"oval:org.mitre.oval:def:8242","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242"},{"name":"http://www.adobe.com/support/security/bulletins/apsb10-02.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb10-02.html"},{"name":"RHSA-2010:0060","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0060.html"},{"name":"ADV-2010-0103","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/0103"},{"name":"1023446","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1023446"},{"name":"61690","refsource":"OSVDB","url":"http://osvdb.org/61690"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=554293","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=554293"},{"name":"acrobat-reader-u3d-code-execution(55551)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55551"},{"name":"38215","refsource":"SECUNIA","url":"http://secunia.com/advisories/38215"},{"name":"SUSE-SA:2010:008","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html"},{"name":"TA10-013A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA10-013A.html"},{"name":"37758","refsource":"BID","url":"http://www.securityfocus.com/bid/37758"}]}}}},"cveMetadata":{"assignerOrgId":"078d4453-3bcd-4900-85e6-15281da43538","assignerShortName":"adobe","cveId":"CVE-2009-3953","datePublished":"2010-01-13T19:00:00.000Z","dateReserved":"2009-11-16T00:00:00.000Z","dateUpdated":"2025-10-22T00:05:53.712Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-01-13 19:30:00","lastModifiedDate":"2026-04-21 21:12:20","problem_types":["CWE-787","n/a","CWE-787 CWE-787 Out-of-bounds Write"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.1.4","matchCriteriaId":"C1329474-A9CD-44C3-828C-A0D53418300B"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0","versionEndExcluding":"8.2","matchCriteriaId":"9670133C-09FA-41F2-B0F7-BFE960E30B71"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"9.3","matchCriteriaId":"EA95CC75-BF25-4BEB-B646-ACDBBE32AF4F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*","matchCriteriaId":"4781BF1E-8A4E-4AFF-9540-23D523EE30DD"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:suse:linux_enterprise_debuginfo:11:-:*:*:*:*:*:*","matchCriteriaId":"C76D0C17-2AFF-4209-BBCD-36166DF7F974"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*","matchCriteriaId":"FBF7B6A8-3DF9-46EC-A90E-6EF68C39F883"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*","matchCriteriaId":"A01C8B7E-EB19-40EA-B1D2-9AE5EA536C95"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise:10.0:sp2:*:*:*:*:*:*","matchCriteriaId":"6A3B50EE-F432-40BE-B422-698955A6058D"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise:10.0:sp3:*:*:*:*:*:*","matchCriteriaId":"1193A7E6-DCB4-4E79-A509-1D6948153A57"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3953","Ordinal":"1","Title":"CVE-2009-3953","CVE":"CVE-2009-3953","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3953","Ordinal":"1","NoteData":"The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration \"array boundary issue,\" a different vulnerability than CVE-2009-2994.","Type":"Description","Title":"CVE-2009-3953"},{"CveYear":"2009","CveId":"3953","Ordinal":"2","NoteData":"2010-01-13","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3953","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}