VYPR
High severity8.8CISA KEVNVD Advisory· Published Jan 13, 2010· Updated Apr 21, 2026

CVE-2009-3953

CVE-2009-3953

Description

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.

Affected products

6
  • cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
    Range: >=7.0,<7.1.4
  • cpe:2.3:a:suse:linux_enterprise_debuginfo:11:-:*:*:*:*:*:*
  • OpenSUSE/openSUSE2 versions
    cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise:10.0:sp2:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:suse:linux_enterprise:10.0:sp2:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise:10.0:sp3:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.