CVE-2009-1492

EXPLOITED

Adobe Acrobat < 7.1.1 - Resource Management Error

Title source: rule

Description

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Arr1val · textremotelinux
https://www.exploit-db.com/exploits/8569

References (27)

... and 7 more

Scores

EPSS 0.6806
EPSS Percentile 98.6%

Details

VulnCheck KEV 2010-01-20
CWE
CWE-399
Status published
Products (2)
adobe/acrobat 7.0 - 7.1.1
adobe/acrobat_reader 7.0 - 7.1.1
Published Apr 30, 2009
Tracked Since Feb 18, 2026