CVE-2009-3459 describes a heap-based buffer overflow vulnerability affecting Adobe Reader and Acrobat versions 7.x, 8.x, and 9.x. This flaw allows remote attackers to execute arbitrary code by crafting a malicious PDF file that corrupts memory. With a CVSS score of 9.3, it is a critical vulnerability, requiring user interaction (opening a PDF) but allowing full compromise of confidentiality, integrity, and availability. The vulnerability was actively exploited in the wild in October 2009, and multiple Metasploit modules and ExploitDB entries exist, indicating readily available exploit code. Despite its past exploitation and high severity, there is minimal current community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, < 7.1.4CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.1.7CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.2CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 7.0, < 7.1.4CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.1.7CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.