CVE-2009-1493

EXPLOITED

Adobe Reader - Resource Management Error

Title source: rule

Description

The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Arr1val · textremotelinux
https://www.exploit-db.com/exploits/8570

Scores

EPSS 0.7620
EPSS Percentile 98.9%

Exploitation Intel

VulnCheck KEV 2010-01-20

Classification

CWE
CWE-399
Status draft

Affected Products (2)

adobe/reader
adobe/reader

Timeline

Published Apr 30, 2009
Tracked Since Feb 18, 2026