CVE-2009-1862

Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
adobeacrobat
9.0 ≤
𝑥
≤ 9.1.2
adobeacrobat_reader
9.0 ≤
𝑥
≤ 9.1.2
adobeflash_player
9.0 ≤
𝑥
≤ 9.0.159.0
adobeflash_player
10.0 ≤
𝑥
≤ 10.0.22.87
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
karmic
Fixed 10.0.32.18-1karmic2
released
jaunty
Fixed 10.0.32.18-1jaunty1
released
intrepid
Fixed 10.0.32.18-1intrepid1
released
hardy
Fixed 10.0.32.18-1hardy1
released
dapper
dne
flashplugin-nonfree
karmic
Fixed 10.0.32.18ubuntu1
released
jaunty
Fixed 10.0.32.18ubuntu0.9.04.1
released
intrepid
Fixed 10.0.32.18ubuntu0.8.10.1
released
hardy
Fixed 9.0.246.0ubuntu1
released
dapper
ignored
References