Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2009-1492

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

  • Published: Apr 30, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-1492
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 9.3
  • AV:N/AC:M/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
adobe / acrobat 7.0 7.1.1.x
adobe / acrobat 8.0 8.1.4.x
adobe / acrobat 9.0 9.1.x
adobe / acrobat_reader 7.0 7.1.1.x
adobe / acrobat_reader 8.0 8.1.4.x
adobe / acrobat_reader 9.0 9.1.x