Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-3459

97
FAUCET Score

CVE-2009-3459 describes a heap-based buffer overflow vulnerability affecting Adobe Reader and Acrobat versions 7.x, 8.x, and 9.x. This flaw allows remote attackers to execute arbitrary code by crafting a malicious PDF file that corrupts memory. With a CVSS score of 9.3, it is a critical vulnerability, requiring user interaction (opening a PDF) but allowing full compromise of confidentiality, integrity, and availability. The vulnerability was actively exploited in the wild in October 2009, and multiple Metasploit modules and ExploitDB entries exist, indicating readily available exploit code. Despite its past exploitation and high severity, there is minimal current community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.0, < 7.1.4CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
>= 8.0, < 8.1.7CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
>= 9.0, < 9.2CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
>= 7.0, < 7.1.4CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
>= 8.0, < 8.1.7CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
86.58%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Added to KEV · May 20, 2026
Metasploit: Adobe FlateDecode Stream Predictor 02 Integer Overflow · Oct 8, 2009
ExploitDB: EDB-16652 · Sep 25, 2010
This CVE's current EPSS score of 0.8658 is in the 100th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

adobepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: acroread-0:8.1.7-1
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: acroread-0:8.1.7-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: acroread-0:8.1.7-1.el5
View patch

Vendor Advisories (1)

redhatCVE-2009-3459Critical

acroread: heap overflow fix in version 8.1.7 (APSB09-15)

Oct 8, 2009

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
blogs.adobe.com / psirt/2009/10/adobe_reader_and_acrobat_issue_1.html
Broken LinkVendor Advisory
isc.sans.org / diary.html
Not Applicable
secunia.com / advisories/36983
Vendor Advisory
securitytracker.com / id
Broken Link
exchange.xforce.ibmcloud.com / vulnerabilities/53691
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6534
Broken Link
adobe.com / support/security/bulletins/apsb09-15.html
PatchVendor Advisory
iss.net / threats/348.html
Broken Link
securityfocus.com / bid/36600
Broken Link
us-cert.gov / cas/techalerts/TA09-286B.html
US Government Resource
vupen.com / english/advisories/2009/2851
Vendor Advisory
vupen.com / english/advisories/2009/2898
Vendor Advisory