CVE-2009-3956
published 2010-01-13CVE-2009-3956: The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.73%
94.0th percentile
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.
Affected
97 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 9.2 | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-27hw-76jw-48hx: The default configuration of Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-02
CVE-2009-3956 [HIGH] GHSA-27hw-76jw-48hx: The default configuration of Adobe Reader and Acrobat 9
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.
Red Hat
acroread: script injection vulnerability (APSB10-02)
vendor_redhat·2010-01-12·CVSS 10.0
CVE-2009-3956 [CRITICAL] acroread: script injection vulnerability (APSB10-02)
acroread: script injection vulnerability (APSB10-02)
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.
Suricata
ET WEB_CLIENT Possible Adobe Reader and Acrobat Forms Data Format Remote Security Bypass Attempt
suricata·2010-07-30
CVE-2009-3956 ET WEB_CLIENT Possible Adobe Reader and Acrobat Forms Data Format Remote Security Bypass Attempt
ET WEB_CLIENT Possible Adobe Reader and Acrobat Forms Data Format Remote Security Bypass Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Possible Adobe Reader and Acrobat Forms Data Format Remote Security Bypass Attempt"; flow:established,to_client; file.data; content:"%FDF-"; fast_pattern; depth:600; content:"/F(JavaScript|3a|"; nocase; distance:0; reference:url,www.securityfocus.com/bid/37763; reference:cve,2009-3956; reference:url,www.stratsec.net/files/SS-2010-001_Stratsec_Acrobat_Script_Injection_Security_Advisory_v1.0.pdf; classtype:attempted-user; sid:2010664; rev:7; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2010_07_30, cve CVE_2009_3956, deployment Perimeter, confidence Me
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlhttp://secunia.com/advisories/38138http://secunia.com/advisories/38215http://www.adobe.com/support/security/bulletins/apsb10-02.htmlhttp://www.packetstormsecurity.org/1001-exploits/SS-2010-001.txthttp://www.redhat.com/support/errata/RHSA-2010-0060.htmlhttp://www.securityfocus.com/bid/37763http://www.securitytracker.com/id?1023446http://www.stratsec.net/files/SS-2010-001_Stratsec_Acrobat_Script_Injection_Security_Advisory_v1.0.pdfhttp://www.us-cert.gov/cas/techalerts/TA10-013A.htmlhttp://www.vupen.com/english/advisories/2010/0103https://bugzilla.redhat.com/show_bug.cgi?id=554296https://exchange.xforce.ibmcloud.com/vulnerabilities/55554https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8327http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlhttp://secunia.com/advisories/38138http://secunia.com/advisories/38215http://www.adobe.com/support/security/bulletins/apsb10-02.htmlhttp://www.packetstormsecurity.org/1001-exploits/SS-2010-001.txthttp://www.redhat.com/support/errata/RHSA-2010-0060.htmlhttp://www.securityfocus.com/bid/37763http://www.securitytracker.com/id?1023446http://www.stratsec.net/files/SS-2010-001_Stratsec_Acrobat_Script_Injection_Security_Advisory_v1.0.pdfhttp://www.us-cert.gov/cas/techalerts/TA10-013A.htmlhttp://www.vupen.com/english/advisories/2010/0103https://bugzilla.redhat.com/show_bug.cgi?id=554296https://exchange.xforce.ibmcloud.com/vulnerabilities/55554https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8327
2010-01-13
Published