acroread: multiple code execution flaws (APSB10-02)
Published Jan 13, 2010 ·Due Jun 22, 2022
8.8
HIGHCVSS 3.1
EPSS 83.22%
Description
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.
Affected products
No data.
Configuration 1
Configuration 2
- 11
- 11.1
- 11.2
- 10.0
- 10.0
No data.
Extras for RHEL 3
acroread-0:9.3-3
Fixed · RHSA-2010:0060
Extras for RHEL 4
acroread-0:9.3-1.el4
Fixed · RHSA-2010:0038
Supplementary for Red Hat Enterprise Linux 5
acroread-0:9.3-1.el5
Fixed · RHSA-2010:0037
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | acroread-0:9.3-3 | Fixed | RHSA-2010:0060 |
| Extras for RHEL 4 | acroread-0:9.3-1.el4 | Fixed | RHSA-2010:0038 |
| Supplementary for Red Hat Enterprise Linux 5 | acroread-0:9.3-1.el5 | Fixed | RHSA-2010:0037 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
Jun 8, 2022
Patch Due
Jun 22, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 4, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 83.22% (0.83219) | 99.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 83.57% (0.83574) | 99.65th | v5 (v2026.06.15) |
| Jun 11, 2025 | 90.51% (0.90514) | 99.58th | v4 (v2025.03.14) |
| Mar 17, 2025 | 91.83% (0.91826) | 99.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.90% (0.96904) | 99.77th | v3 (v2023.03.01) |
| Jul 13, 2024 | 96.56% (0.96557) | 99.63th | v3 (v2023.03.01) |
| Jun 29, 2024 | 96.81% (0.96814) | 99.70th | v3 (v2023.03.01) |
| Jun 1, 2024 | 97.14% (0.97142) | 99.80th | v3 (v2023.03.01) |
| Apr 17, 2024 | 97.24% (0.97242) | 99.83th | v3 (v2023.03.01) |
| Mar 2, 2024 | 97.26% (0.97263) | 99.83th | v3 (v2023.03.01) |
| Jan 16, 2024 | 97.23% (0.97227) | 99.80th | v3 (v2023.03.01) |
| Dec 2, 2023 | 97.08% (0.97077) | 99.71th | v3 (v2023.03.01) |
| Oct 19, 2023 | 97.18% (0.97183) | 99.74th | v3 (v2023.03.01) |
| Sep 6, 2023 | 96.99% (0.96988) | 99.62th | v3 (v2023.03.01) |
| Jul 25, 2023 | 97.27% (0.97267) | 99.76th | v3 (v2023.03.01) |
| Jun 11, 2023 | 97.25% (0.97249) | 99.74th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.33% (0.97330) | 99.76th | v3 (v2023.03.01) |
| Mar 6, 2023 | 92.12% (0.92123) | 99.90th | v2 (v2022.01.01) |
| Jul 18, 2022 | 92.12% (0.92123) | 99.90th | v2 (v2022.01.01) |
| Jul 17, 2022 | 84.95% (0.84952) | 99.65th | v2 (v2022.01.01) |
| Feb 4, 2022 | 92.12% (0.92123) | 99.89th | v2 (v2022.01.01) |
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://osvdb.org/61690 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/38138 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/38215 third-party-advisoryx_refsource_SECUNIABroken Link
- http://www.adobe.com/support/security/bulletins/apsb10-02.html x_refsource_CONFIRMNot ApplicablePatchVendor Advisory
- http://www.metasploit.com/modules/exploit/windows/fileformat/adobe_u3d_meshdecl x_refsource_MISCThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0060.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/bid/37758 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1023446 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2010/0103 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-3953 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=554293 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55551 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2009-3953
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8242 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3953 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2009-3953
Change history (0)
No recorded changes yet.