CVE-2009-0520

Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
adobeair
1.5
adobeflash_player
𝑥
≤ 10.0.12.36
adobeflash_player
7.0
adobeflash_player
7.0.1
adobeflash_player
7.0.25
adobeflash_player
7.0.63
adobeflash_player
7.0.63
adobeflash_player
7.0.69.0
adobeflash_player
7.0.70.0
adobeflash_player
7.1
adobeflash_player
7.1.1
adobeflash_player
7.2
adobeflash_player
8.0
adobeflash_player
8.0
adobeflash_player
8.0
adobeflash_player
8.0.24.0
adobeflash_player
8.0.34.0
adobeflash_player
8.0.35.0
adobeflash_player
8.0.39.0
adobeflash_player
9.0.16
adobeflash_player
9.0.20
adobeflash_player
9.0.20.0
adobeflash_player
9.0.28
adobeflash_player
9.0.28.0
adobeflash_player
9.0.31.0
adobeflash_player
9.0.45.0
adobeflash_player
9.0.47.0
adobeflash_player
9.0.48.0
adobeflash_player
9.0.112.0
adobeflash_player
9.0.114.0
adobeflash_player
9.0.115.0
adobeflash_player
9.0.124.0
adobeflash_player
10.0.0.584
adobeflash_player
10.0.12.10
adobeflash_player_for_linux
𝑥
≤ 10.0.15.3
adobeflex
3.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
karmic
not-affected
jaunty
not-affected
intrepid
Fixed 10.0.22.87-2intrepid1
released
hardy
Fixed 10.0.22.87-2
released
gutsy
Fixed 10.0.22.87-0gutsy3
released
dapper
dne
flashplugin-nonfree
karmic
Fixed 10.0.22.87ubuntu1
released
jaunty
Fixed 10.0.22.87ubuntu1
released
intrepid
Fixed 10.0.22.87ubuntu1~intrepid1
released
hardy
Fixed 9.0.159.0ubuntu1~hardy1
released
gutsy
Fixed 9.0.159.0ubuntu1~gutsy1
released
dapper
ignored
References