CVE-2009-0520

EUVD-2009-0524
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
adobeair
1.5
adobeflash_player
𝑥
≤ 10.0.12.36
adobeflash_player
7.0
adobeflash_player
7.0.1
adobeflash_player
7.0.25
adobeflash_player
7.0.63
adobeflash_player
7.0.63
adobeflash_player
7.0.69.0
adobeflash_player
7.0.70.0
adobeflash_player
7.1
adobeflash_player
7.1.1
adobeflash_player
7.2
adobeflash_player
8.0
adobeflash_player
8.0
adobeflash_player
8.0
adobeflash_player
8.0.24.0
adobeflash_player
8.0.34.0
adobeflash_player
8.0.35.0
adobeflash_player
8.0.39.0
adobeflash_player
9.0.16
adobeflash_player
9.0.20
adobeflash_player
9.0.20.0
adobeflash_player
9.0.28
adobeflash_player
9.0.28.0
adobeflash_player
9.0.31.0
adobeflash_player
9.0.45.0
adobeflash_player
9.0.47.0
adobeflash_player
9.0.48.0
adobeflash_player
9.0.112.0
adobeflash_player
9.0.114.0
adobeflash_player
9.0.115.0
adobeflash_player
9.0.124.0
adobeflash_player
10.0.0.584
adobeflash_player
10.0.12.10
adobeflash_player_for_linux
𝑥
≤ 10.0.15.3
adobeflex
3.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
dapper
dne
gutsy
Fixed 10.0.22.87-0gutsy3
released
hardy
Fixed 10.0.22.87-2
released
intrepid
Fixed 10.0.22.87-2intrepid1
released
jaunty
not-affected
karmic
not-affected
flashplugin-nonfree
dapper
ignored
gutsy
Fixed 9.0.159.0ubuntu1~gutsy1
released
hardy
Fixed 9.0.159.0ubuntu1~hardy1
released
intrepid
Fixed 10.0.22.87ubuntu1~intrepid1
released
jaunty
Fixed 10.0.22.87ubuntu1
released
karmic
Fixed 10.0.22.87ubuntu1
released
References