CVE-2009-2983

Exp

Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

Published: 2009-10-19 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-2983 is rated High Exploit Risk (84.3/100): CVSS Critical severity, with high exploitation likelihood (EPSS 41.91%, 97th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2009-2983

EDB-ID Source Kind Published Link
33283 exploit_db edb 2009-10-13 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2009-2983

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-22 43.91% 41.91% -2.00%
2 2026-01-08 57.48% 43.91% -13.57%
3 2025-03-30 57.48%

Full EPSS history (13 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-2983

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.3 2.0 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
8.6 10.0 [email protected]

Weakness enumeration for CVE-2009-2983

OS Trackers for CVE-2009-2983

vendor priority summary link
gentoo normal CVE-2009-2983: 1 GLSA(s) (200910-03), 1 atom(s) (app-text/acroread); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2009-2983
redhat critical https://access.redhat.com/security/cve/CVE-2009-2983
ubuntu medium CVE-2009-2983 medium priority: Ubuntu including 1 source packages (acroread), 6 status rows across 6 suites (dapper, hardy, intrepid, jaunty, karmic, upstream): released 5, ignored 1. https://ubuntu.com/security/CVE-2009-2983

NVD evaluator notes for CVE-2009-2983

Impact: Per: http://www.adobe.com/support/security/bulletins/apsb09-15.html Critical vulnerabilities have been identified in Adobe Reader 9.1.3 and Acrobat 9.1.3, Adobe Reader 8.1.6 and Acrobat 8.1.6 for Windows, Macintosh and UNIX, and Adobe Reader 7.1.3 and Acrobat 7.1.3 for Windows and Macintosh. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. This update represents the second quarterly security update for Adobe Reader and Acrobat. Adobe recommends users of Adobe Reader 9.1.3 and Acrobat 9.1.3 and earlier versions update to Adobe Reader 9.2 and Acrobat 9.2. Adobe recommends users of Acrobat 8.1.6 and earlier versions update to Acrobat 8.1.7, and users of Acrobat 7.1.3 and earlier versions update to Acrobat 7.1.4. For Adobe Reader users who cannot update to Adobe Reader 9.2, Adobe has provided the Adobe Reader 8.1.7 and Adobe Reader 7.1.4 updates. Updates apply to all platforms: Windows, Macintosh and UNIX. Affected software versions Adobe Reader 9.1.3 and earlier versions for Windows, Macintosh, and UNIX Adobe Acrobat 9.1.3 and earlier versions for Windows and Macintosh

Solution: Solution: Per: http://www.adobe.com/support/security/bulletins/apsb09-15.html Adobe Reader Adobe Reader users on Windows can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows. Adobe Reader users on Macintosh can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Macintosh. Adobe Reader users on UNIX can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Unix. Acrobat Acrobat Standard and Pro users on Windows can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows. Acrobat Pro Extended users on Windows can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=158&platform=Windows Acrobat 3D users on Windows can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=112&platform=Windows. Acrobat Pro users on Macintosh can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh.

Affected software / configurations for CVE-2009-2983

Vendor Product Version Raw CPE
adobe acrobat <= 9.1.3 cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
adobe acrobat 7.0 cpe:2.3:a:adobe:acrobat:7.0:*:*:*:*:*:*:*
adobe acrobat 7.0.1 cpe:2.3:a:adobe:acrobat:7.0.1:*:*:*:*:*:*:*
adobe acrobat 7.0.2 cpe:2.3:a:adobe:acrobat:7.0.2:*:*:*:*:*:*:*
adobe acrobat 7.0.3 cpe:2.3:a:adobe:acrobat:7.0.3:*:*:*:*:*:*:*
adobe acrobat 7.0.4 cpe:2.3:a:adobe:acrobat:7.0.4:*:*:*:*:*:*:*
adobe acrobat 7.0.5 cpe:2.3:a:adobe:acrobat:7.0.5:*:*:*:*:*:*:*
adobe acrobat 7.0.6 cpe:2.3:a:adobe:acrobat:7.0.6:*:*:*:*:*:*:*
adobe acrobat 7.0.7 cpe:2.3:a:adobe:acrobat:7.0.7:*:*:*:*:*:*:*
adobe acrobat 7.0.8 cpe:2.3:a:adobe:acrobat:7.0.8:*:*:*:*:*:*:*
adobe acrobat 7.0.9 cpe:2.3:a:adobe:acrobat:7.0.9:*:*:*:*:*:*:*
adobe acrobat 7.1.0 cpe:2.3:a:adobe:acrobat:7.1.0:*:*:*:*:*:*:*
adobe acrobat 7.1.1 cpe:2.3:a:adobe:acrobat:7.1.1:*:*:*:*:*:*:*
adobe acrobat 7.1.3 cpe:2.3:a:adobe:acrobat:7.1.3:*:*:*:*:*:*:*
adobe acrobat 8.0 cpe:2.3:a:adobe:acrobat:8.0:*:*:*:*:*:*:*
adobe acrobat 8.1 cpe:2.3:a:adobe:acrobat:8.1:*:*:*:*:*:*:*
adobe acrobat 8.1.1 cpe:2.3:a:adobe:acrobat:8.1.1:*:*:*:*:*:*:*
adobe acrobat 8.1.2 cpe:2.3:a:adobe:acrobat:8.1.2:*:*:*:*:*:*:*
adobe acrobat 8.1.3 cpe:2.3:a:adobe:acrobat:8.1.3:*:*:*:*:*:*:*
adobe acrobat 8.1.4 cpe:2.3:a:adobe:acrobat:8.1.4:*:*:*:*:*:*:*
adobe acrobat 8.1.6 cpe:2.3:a:adobe:acrobat:8.1.6:*:*:*:*:*:*:*
adobe acrobat 9.0 cpe:2.3:a:adobe:acrobat:9.0:*:*:*:*:*:*:*
adobe acrobat 9.1.1 cpe:2.3:a:adobe:acrobat:9.1.1:*:*:*:*:*:*:*
adobe acrobat 9.1.2 cpe:2.3:a:adobe:acrobat:9.1.2:*:*:*:*:*:*:*
adobe acrobat_reader <= 9.1.3 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
adobe acrobat_reader 7.0 cpe:2.3:a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*
adobe acrobat_reader 7.0.1 cpe:2.3:a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*
adobe acrobat_reader 7.0.2 cpe:2.3:a:adobe:acrobat_reader:7.0.2:*:*:*:*:*:*:*
adobe acrobat_reader 7.0.3 cpe:2.3:a:adobe:acrobat_reader:7.0.3:*:*:*:*:*:*:*
adobe acrobat_reader 7.0.4 cpe:2.3:a:adobe:acrobat_reader:7.0.4:*:*:*:*:*:*:*
adobe acrobat_reader 7.0.5 cpe:2.3:a:adobe:acrobat_reader:7.0.5:*:*:*:*:*:*:*
adobe acrobat_reader 7.0.6 cpe:2.3:a:adobe:acrobat_reader:7.0.6:*:*:*:*:*:*:*
adobe acrobat_reader 7.0.7 cpe:2.3:a:adobe:acrobat_reader:7.0.7:*:*:*:*:*:*:*
adobe acrobat_reader 7.0.8 cpe:2.3:a:adobe:acrobat_reader:7.0.8:*:*:*:*:*:*:*
adobe acrobat_reader 7.0.9 cpe:2.3:a:adobe:acrobat_reader:7.0.9:*:*:*:*:*:*:*
adobe acrobat_reader 7.1.0 cpe:2.3:a:adobe:acrobat_reader:7.1.0:*:*:*:*:*:*:*
adobe acrobat_reader 7.1.1 cpe:2.3:a:adobe:acrobat_reader:7.1.1:*:*:*:*:*:*:*
adobe acrobat_reader 7.1.3 cpe:2.3:a:adobe:acrobat_reader:7.1.3:*:*:*:*:*:*:*
adobe acrobat_reader 8.0 cpe:2.3:a:adobe:acrobat_reader:8.0:*:*:*:*:*:*:*
adobe acrobat_reader 8.1 cpe:2.3:a:adobe:acrobat_reader:8.1:*:*:*:*:*:*:*
adobe acrobat_reader 8.1.1 cpe:2.3:a:adobe:acrobat_reader:8.1.1:*:*:*:*:*:*:*
adobe acrobat_reader 8.1.2 cpe:2.3:a:adobe:acrobat_reader:8.1.2:*:*:*:*:*:*:*
adobe acrobat_reader 8.1.3 cpe:2.3:a:adobe:acrobat_reader:8.1.3:*:*:*:*:*:*:*
adobe acrobat_reader 8.1.4 cpe:2.3:a:adobe:acrobat_reader:8.1.4:*:*:*:*:*:*:*
adobe acrobat_reader 8.1.5 cpe:2.3:a:adobe:acrobat_reader:8.1.5:*:*:*:*:*:*:*
adobe acrobat_reader 8.1.6 cpe:2.3:a:adobe:acrobat_reader:8.1.6:*:*:*:*:*:*:*
adobe acrobat_reader 9.0 cpe:2.3:a:adobe:acrobat_reader:9.0:*:*:*:*:*:*:*
adobe acrobat_reader 9.1 cpe:2.3:a:adobe:acrobat_reader:9.1:*:*:*:*:*:*:*
adobe acrobat_reader 9.1.1 cpe:2.3:a:adobe:acrobat_reader:9.1.1:*:*:*:*:*:*:*
adobe acrobat_reader 9.1.2 cpe:2.3:a:adobe:acrobat_reader:9.1.2:*:*:*:*:*:*:*

References for CVE-2009-2983

cvelogic Threat Intelligence