CVE-2009-3958 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 52.6% (pctl 99)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 52.59% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-01-13 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat reader |
| apple | mac os x |
| microsoft | windows |
| unix | unix |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe GetPlus get_atlcom 1.6.2.48 - ActiveX Remote Execution | 2010-01-17 |
References
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://www.adobe.com/support/security/bulletins/apsb10-02.html
- http://www.kb.cert.org/vuls/id/773545
- http://www.securityfocus.com/bid/37759
- http://www.securitytracker.com/id?1023446
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html
- http://www.vupen.com/english/advisories/2010/0103
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55556
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8455
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://www.adobe.com/support/security/bulletins/apsb10-02.html
- http://www.kb.cert.org/vuls/id/773545
- http://www.securityfocus.com/bid/37759
- http://www.securitytracker.com/id?1023446
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html
- http://www.vupen.com/english/advisories/2010/0103
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55556
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8455
→ the Explorer · watch your stack · NVD