« Volver al listado

CVE-2009-3460

Estado: ModificadaAlta (9.3)—

Adobe Acrobat v9.x anteriores a v9.2, v8.x anteriores a v8.1.7, y posiblemente v7.x anteriores a v7.1.4 permite a los atacantes provocar una denegación de servicio (corrupción de memoria) o probablemente ejecutar código de su elección a través de vectores de ataque sin especificar.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-3460",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-10-19T22:30:00.750",
  "references": [
    {
      "url": "http://securitytracker.com/id?1023007",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.adobe.com/support/security/bulletins/apsb09-15.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/36638",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA09-286B.html",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/2898",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6550",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://securitytracker.com/id?1023007",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.adobe.com/support/security/bulletins/apsb09-15.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/36638",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA09-286B.html",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/2898",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6550",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Adobe Acrobat v9.x anteriores a v9.2, v8.x anteriores a v8.1.7, y posiblemente v7.x anteriores a v7.1.4 permite a los atacantes provocar una denegación de servicio (corrupción de memoria) o probablemente ejecutar código de su elección a través de vectores de ataque sin especificar."
    }
  ],
  "lastModified": "2026-06-16T23:11:38.927",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84209F08-D75D-4C02-94E4-5942B244E632",
              "versionEndIncluding": "9.1.3"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FECFC942-4F04-420C-A9B4-AE0C0590317F"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F81817F2-1E3A-4A52-88F1-6B614A2A1F0A"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFFFFF0D-A80F-4B67-BEE2-86868EF7AA37"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DC97A87-2652-4AD6-8E10-419A9AC9C245"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E1F71AE-3591-499E-B09F-AAC4E38F1CF2"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D75174C-EBF9-4117-9E66-80E847012853"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69B0305A-51D3-4E09-B96C-54B0ED921DA3"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9762FE57-837B-4FFA-9813-AC038450EB2B"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0055A38C-E421-40A1-8BC7-11856A20B8F0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "758CC9EE-8929-405B-A845-83BAAECCB2AD"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24A7CF98-27EC-406A-98E2-ACC1AAAF5C93"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC1BD70D-7A92-4309-A40C-9BD500997390"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:7.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21AC1961-12F7-456F-9CE4-9AAF116CF141"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26AE76F7-D7F6-4AF2-A5C6-708B5642C288"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "749FFB51-65D4-4A4B-95F3-742440276897"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:8.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8665E53-EC1E-4B95-9064-2565BC12113E"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:8.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24218FDA-F9DA-465A-B5D5-76A55C7EE04E"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:8.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2C5F1C5-85CD-47B9-897F-E51D6902AF72"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:8.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0E190FF-3EBC-44AB-8072-4D964E843E8A"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:8.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B95C0A99-42E4-40A9-BF61-507E4E4DC052"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AA53564-9ACD-4CFB-9AAC-A77440026A57"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:9.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F475858-DCE2-4C93-A51A-04718DF17593"
            },
            {
              "criteria": "cpe:2.3:a:adobe:acrobat:9.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88687272-4CD0-42A2-B727-C322ABDE3549"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorImpact": "Per: http://www.adobe.com/support/security/bulletins/apsb09-15.html\r\n\r\n\r\nThis update resolves a memory corruption issue that could potentially lead to code execution. This issue is specific to Acrobat and does not affect Adobe Reader. (CVE-2009-3460).\r\nNOTE: this issue is resolved in the Acrobat 9.2 and 8.1.7 updates.",
  "sourceIdentifier": "psirt@adobe.com",
  "evaluatorSolution": "Per: http://www.adobe.com/support/security/bulletins/apsb09-15.html\r\n\r\nSolution\r\n\r\n\r\nAcrobat\r\n\r\nAcrobat Standard and Pro users on Windows can find the appropriate update here:\r\nhttp://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows.\r\n\r\nAcrobat Pro Extended users on Windows can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=158&platform=Windows\r\n\r\nAcrobat 3D users on Windows can find the appropriate update here:\r\nhttp://www.adobe.com/support/downloads/product.jsp?product=112&platform=Windows.\r\n\r\nAcrobat Pro users on Macintosh can find the appropriate update here:\r\nhttp://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh."
}