Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-0658

86
FAUCET Score

CVE-2009-0658 is a critical buffer overflow vulnerability affecting Adobe Reader and Acrobat versions 9.0 and earlier. This flaw allows remote attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted PDF document, potentially involving a non-JavaScript function call or an embedded JBIG2 image stream. With a CVSS score of 7.8 (High), the vulnerability requires user interaction (opening the PDF) but can lead to complete compromise of confidentiality, integrity, and availability. It was actively exploited in the wild in February 2009 by Trojan.Pidief.E, and multiple Metasploit modules and ExploitDB entries confirm the availability of exploit code, despite limited recent community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.0, <= 7.1.1CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
>= 8.0, <= 8.1.4CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat:9.0:*:*:*:*:*:*:*
>= 7.0, <= 7.1.1CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
>= 8.0, <= 8.1.4CPE matchmatch criteria
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
87.72%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Metasploit: Adobe JBIG2Decode Heap Corruption · Feb 19, 2009
ExploitDB: EDB-16672 · Sep 25, 2010
This CVE's current EPSS score of 0.8772 is in the 100th percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: acroread-0:8.1.4-1
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: acroread-0:8.1.4-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: acroread-0:8.1.4-1.el5
View patch
adobevendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2009-0658Critical

acroread: multiple JBIG2-related security flaws

Feb 19, 2009

References

isc.sans.org / diary.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2009-03/msg00005.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2009-04/msg00010.html
Third Party Advisory
osvdb.org / 52073
Broken Link
secunia.com / advisories/33901
Third Party Advisory
secunia.com / advisories/34392
Third Party Advisory
secunia.com / advisories/34490
Third Party Advisory
secunia.com / advisories/34706
Third Party Advisory
secunia.com / advisories/34790
Third Party Advisory
security.gentoo.org / glsa/glsa-200904-17.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/48825
VDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5697
Tool Signature
sunsolve.sun.com / search/document.do
Third Party Advisory
exploit-db.com / exploits/8090
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/8099
Third Party AdvisoryVDB Entry
adobe.com / support/security/advisories/apsa09-01.html
Vendor Advisory
adobe.com / support/security/bulletins/apsb09-04.html
Vendor Advisory
kb.cert.org / vuls/id/905281
Third Party AdvisoryUS Government Resource
redhat.com / support/errata/RHSA-2009-0376.html
Third Party Advisory
securityfocus.com / bid/33751
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
shadowserver.org / wiki/pmwiki.php
Third Party Advisory
symantec.com / security_response/writeup.jsp
Third Party Advisory
us-cert.gov / cas/techalerts/TA09-051A.html
Third Party AdvisoryUS Government Resource
vupen.com / english/advisories/2009/0472
Third Party Advisory
vupen.com / english/advisories/2009/1019
Third Party Advisory