Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-3956


The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.


Published

2010-01-13T19:30:00.513

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-16

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe acrobat ≤ 9.2 Yes
Application adobe acrobat 3.0 Yes
Application adobe acrobat 3.1 Yes
Application adobe acrobat 4.0 Yes
Application adobe acrobat 4.0.5 Yes
Application adobe acrobat 4.0.5a Yes
Application adobe acrobat 4.0.5c Yes
Application adobe acrobat 5.0 Yes
Application adobe acrobat 5.0.5 Yes
Application adobe acrobat 5.0.6 Yes
Application adobe acrobat 5.0.10 Yes
Application adobe acrobat 6.0 Yes
Application adobe acrobat 6.0.1 Yes
Application adobe acrobat 6.0.2 Yes
Application adobe acrobat 6.0.3 Yes
Application adobe acrobat 6.0.4 Yes
Application adobe acrobat 6.0.5 Yes
Application adobe acrobat 6.0.6 Yes
Application adobe acrobat 7.0 Yes
Application adobe acrobat 7.0.1 Yes
Application adobe acrobat 7.0.2 Yes
Application adobe acrobat 7.0.3 Yes
Application adobe acrobat 7.0.4 Yes
Application adobe acrobat 7.0.5 Yes
Application adobe acrobat 7.0.6 Yes
Application adobe acrobat 7.0.7 Yes
Application adobe acrobat 7.0.8 Yes
Application adobe acrobat 7.0.9 Yes
Application adobe acrobat 7.1.0 Yes
Application adobe acrobat 7.1.1 Yes
Application adobe acrobat 7.1.2 Yes
Application adobe acrobat 7.1.3 Yes
Application adobe acrobat 7.1.4 Yes
Application adobe acrobat 8.0 Yes
Application adobe acrobat 8.1 Yes
Application adobe acrobat 8.1.1 Yes
Application adobe acrobat 8.1.2 Yes
Application adobe acrobat 8.1.3 Yes
Application adobe acrobat 8.1.4 Yes
Application adobe acrobat 8.1.5 Yes
Application adobe acrobat 8.1.6 Yes
Application adobe acrobat 8.1.7 Yes
Application adobe acrobat 9.0 Yes
Application adobe acrobat 9.1 Yes
Application adobe acrobat 9.1.1 Yes
Application adobe acrobat 9.1.2 Yes
Application adobe acrobat 9.1.3 Yes
Operating System apple mac_os_x * No
Operating System microsoft windows * No
Application adobe acrobat_reader ≤ 9.2 Yes
Application adobe acrobat_reader 3.0 Yes
Application adobe acrobat_reader 3.01 Yes
Application adobe acrobat_reader 3.02 Yes
Application adobe acrobat_reader 4.0 Yes
Application adobe acrobat_reader 4.0.5 Yes
Application adobe acrobat_reader 4.0.5a Yes
Application adobe acrobat_reader 4.0.5c Yes
Application adobe acrobat_reader 4.5 Yes
Application adobe acrobat_reader 5.0 Yes
Application adobe acrobat_reader 5.0.5 Yes
Application adobe acrobat_reader 5.0.6 Yes
Application adobe acrobat_reader 5.0.7 Yes
Application adobe acrobat_reader 5.0.9 Yes
Application adobe acrobat_reader 5.0.10 Yes
Application adobe acrobat_reader 5.0.11 Yes
Application adobe acrobat_reader 5.1 Yes
Application adobe acrobat_reader 6.0 Yes
Application adobe acrobat_reader 6.0.1 Yes
Application adobe acrobat_reader 6.0.2 Yes
Application adobe acrobat_reader 6.0.3 Yes
Application adobe acrobat_reader 6.0.4 Yes
Application adobe acrobat_reader 6.0.5 Yes
Application adobe acrobat_reader 7.0 Yes
Application adobe acrobat_reader 7.0.1 Yes
Application adobe acrobat_reader 7.0.2 Yes
Application adobe acrobat_reader 7.0.3 Yes
Application adobe acrobat_reader 7.0.4 Yes
Application adobe acrobat_reader 7.0.5 Yes
Application adobe acrobat_reader 7.0.6 Yes
Application adobe acrobat_reader 7.0.7 Yes
Application adobe acrobat_reader 7.0.8 Yes
Application adobe acrobat_reader 7.0.9 Yes
Application adobe acrobat_reader 7.1.0 Yes
Application adobe acrobat_reader 7.1.1 Yes
Application adobe acrobat_reader 7.1.2 Yes
Application adobe acrobat_reader 7.1.3 Yes
Application adobe acrobat_reader 8.0 Yes
Application adobe acrobat_reader 8.1 Yes
Application adobe acrobat_reader 8.1.1 Yes
Application adobe acrobat_reader 8.1.2 Yes
Application adobe acrobat_reader 8.1.4 Yes
Application adobe acrobat_reader 8.1.5 Yes
Application adobe acrobat_reader 8.1.6 Yes
Application adobe acrobat_reader 8.1.7 Yes
Application adobe acrobat_reader 9.0 Yes
Application adobe acrobat_reader 9.1 Yes
Application adobe acrobat_reader 9.1.1 Yes
Application adobe acrobat_reader 9.1.2 Yes
Application adobe acrobat_reader 9.1.3 Yes
Operating System apple mac_os_x * No
Operating System microsoft windows * No
Operating System unix unix * No

References