VulnerabilityModified
CVE-2009-2988
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.
MEDIUM 4.3EPSS 3.52%
Does this matter?
Lower severity and a low EPSS score (3.52%). Track it; it rarely justifies an emergency change on its own.
Description
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 3.52% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- adobe/acrobat · adobe/acrobat reader
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1023007
- http://www.adobe.com/support/security/bulletins/apsb09-15.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/36638
- http://www.us-cert.gov/cas/techalerts/TA09-286B.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2009/2898Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6483
- http://securitytracker.com/id?1023007
- http://www.adobe.com/support/security/bulletins/apsb09-15.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/36638
- http://www.us-cert.gov/cas/techalerts/TA09-286B.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2009/2898Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6483
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.