CVE-2009-2993

EUVD-2009-2978
The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file.  NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
Affected Products (NVD)
VendorProductVersion
adobeacrobat
𝑥
≤ 9.1.3
adobeacrobat
7.0
adobeacrobat
7.0.1
adobeacrobat
7.0.2
adobeacrobat
7.0.3
adobeacrobat
7.0.4
adobeacrobat
7.0.5
adobeacrobat
7.0.6
adobeacrobat
7.0.7
adobeacrobat
7.0.8
adobeacrobat
7.0.9
adobeacrobat
7.1.0
adobeacrobat
7.1.1
adobeacrobat
7.1.3
adobeacrobat
8.0
adobeacrobat
8.1
adobeacrobat
8.1.1
adobeacrobat
8.1.2
adobeacrobat
8.1.3
adobeacrobat
8.1.4
adobeacrobat
8.1.6
adobeacrobat
9.0
adobeacrobat
9.1.1
adobeacrobat
9.1.2
adobeacrobat_reader
𝑥
≤ 9.1.3
adobeacrobat_reader
7.0
adobeacrobat_reader
7.0.1
adobeacrobat_reader
7.0.2
adobeacrobat_reader
7.0.3
adobeacrobat_reader
7.0.4
adobeacrobat_reader
7.0.5
adobeacrobat_reader
7.0.6
adobeacrobat_reader
7.0.7
adobeacrobat_reader
7.0.8
adobeacrobat_reader
7.0.9
adobeacrobat_reader
7.1.0
adobeacrobat_reader
7.1.1
adobeacrobat_reader
7.1.3
adobeacrobat_reader
8.0
adobeacrobat_reader
8.1
adobeacrobat_reader
8.1.1
adobeacrobat_reader
8.1.2
adobeacrobat_reader
8.1.3
adobeacrobat_reader
8.1.4
adobeacrobat_reader
8.1.5
adobeacrobat_reader
8.1.6
adobeacrobat_reader
9.0
adobeacrobat_reader
9.1
adobeacrobat_reader
9.1.1
adobeacrobat_reader
9.1.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
acroread
dapper
ignored
hardy
Fixed 9.2-1
released
intrepid
Fixed 9.2-1intrepid2
released
jaunty
Fixed 9.2-1jaunty1
released
karmic
Fixed 9.2-1karmic1
released