VDB
CVE-2009-0928
CVE-2009-0928
PUBLISHED
CVSS 10 CRITICAL
Heap-based buffer overflow in Adobe Acrobat Reader and Acrobat Professional 7.1.0, 8.1.3, 9.0.0, and other versions allows remote attackers to execute arbitrary code via a PDF file containing a JBIG2 stream with a size inconsistency related to an unspecified table.
EPSS 16.24% · 95.0th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
16.24%
95.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| adobe | acrobat_reader | 5.0.5, 4.0, 4.0.5 |
| adobe | acrobat | 4.0.5a, 4.0.5c, 5.0 |
Timeline
- Mar 25, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 2, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jun 27, 2023 EPSS Score
References
- 20090324 Adobe Reader and Acrobat JBIG2 Encoded Stream Heap Overflow Vulnerability third-party-advisory
- 34790 third-party-advisory
- http://www.adobe.com/support/security/bulletins/apsb09-04.html url
- 34229 vdb
- 34490 third-party-advisory
- 1021892 vdb
- RHSA-2009:0376 vendor-advisory
- 34392 third-party-advisory
- SUSE-SA:2009:014 vendor-advisory
- 34706 third-party-advisory
- 256788 vendor-advisory
- GLSA-200904-17 vendor-advisory
- SUSE-SR:2009:009 vendor-advisory
- ADV-2009-1019 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2009-0928 advisory