← Vulnerability feed

Vulnerability record · CVE-2009-1493 · published 30 April 2009

CVE-2009-1493: Adobe reader vulnerability

Adobe · Reader

The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.

6.8 CVSS 2.0 Medium EPSS 22% · top 2.4% CWE-399 · CWE-399
6.8CVSS 2.0 base score
22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
52References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html Vendor Advisory
http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00001.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html Mailing ListThird Party Advisory
http://osvdb.org/54129 Broken Link
http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt Exploit
http://secunia.com/advisories/34924 Broken Link
http://secunia.com/advisories/35055 Broken Link
http://secunia.com/advisories/35096 Broken Link
http://secunia.com/advisories/35152 Broken Link
http://secunia.com/advisories/35358 Broken Link
http://secunia.com/advisories/35416 Broken Link
http://secunia.com/advisories/35734 Broken Link
http://security.gentoo.org/glsa/glsa-200907-06.xml Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-259028-1 Broken Link
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=926953 Third Party Advisory
http://www.adobe.com/support/security/bulletins/apsb09-06.html Third Party Advisory
http://www.kb.cert.org/vuls/id/970180 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2009-0478.html Third Party Advisory
http://www.securityfocus.com/bid/34740 ExploitThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1022139 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA09-133B.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2009/1189 Broken Link
http://www.vupen.com/english/advisories/2009/1317 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/50146 Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/8570 Third Party AdvisoryVDB Entry
http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html Vendor Advisory
http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00001.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html Mailing ListThird Party Advisory
http://osvdb.org/54129 Broken Link
http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt Exploit
http://secunia.com/advisories/34924 Broken Link
http://secunia.com/advisories/35055 Broken Link
http://secunia.com/advisories/35096 Broken Link
http://secunia.com/advisories/35152 Broken Link
http://secunia.com/advisories/35358 Broken Link
http://secunia.com/advisories/35416 Broken Link
http://secunia.com/advisories/35734 Broken Link
http://security.gentoo.org/glsa/glsa-200907-06.xml Third Party Advisory

Track CVE-2009-1493 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2016-1044Adobe acrobat improper access control vulnerabilityAdobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…EPSS 6.9%10.0CVE-2016-1041Adobe acrobat improper access control vulnerabilityAdobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…EPSS 6.3%10.0CVE-2016-1038Adobe acrobat improper access control vulnerabilityAdobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…EPSS 7.0%9.8CVE-2017-3124Adobe acrobat memory buffer overflow vulnerabilityAdobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable m…EPSS 8.3%9.8CVE-2017-3037Adobe acrobat memory buffer overflow vulnerabilityAdobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerabi…EPSS 6.3%9.8CVE-2017-3010Adobe acrobat memory buffer overflow vulnerabilityAdobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerabi…EPSS 4.6%9.8CVE-2016-4095Adobe acrobat memory buffer overflow vulnerabilityAdobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befo…EPSS 4.0%9.8CVE-2016-7854Adobe acrobat memory buffer overflow vulnerabilityAdobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befo…EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2009-1493), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.