AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-3956

HIGH · CVSS 10 EPSS 7.73% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-01-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2009-3956
Severity
HIGH
CVSS
10
EPSS
7.73%
Windows

Original NVD Description

The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.