CVE-2009-1862

EUVD-2009-1857
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
adobeacrobat
9.0 ≤
𝑥
≤ 9.1.2
adobeacrobat_reader
9.0 ≤
𝑥
≤ 9.1.2
adobeflash_player
9.0 ≤
𝑥
≤ 9.0.159.0
adobeflash_player
10.0 ≤
𝑥
≤ 10.0.22.87
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
dapper
dne
hardy
Fixed 10.0.32.18-1hardy1
released
intrepid
Fixed 10.0.32.18-1intrepid1
released
jaunty
Fixed 10.0.32.18-1jaunty1
released
karmic
Fixed 10.0.32.18-1karmic2
released
flashplugin-nonfree
dapper
ignored
hardy
Fixed 9.0.246.0ubuntu1
released
intrepid
Fixed 10.0.32.18ubuntu0.8.10.1
released
jaunty
Fixed 10.0.32.18ubuntu0.9.04.1
released
karmic
Fixed 10.0.32.18ubuntu1
released
References