CVE-2009-3794

Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
adobeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
adobeadobe_air
𝑥
≤ 1.5.2
adobeadobe_air
1.0
adobeadobe_air
1.0.1
adobeadobe_air
1.1
adobeadobe_air
1.5.1
adobeflash_player
𝑥
≤ 10.0.32.18
adobeflash_player
7.0
adobeflash_player
7.0.1
adobeflash_player
7.0.25
adobeflash_player
7.0.63
adobeflash_player
7.0.69.0
adobeflash_player
7.0.70.0
adobeflash_player
7.1
adobeflash_player
7.1.1
adobeflash_player
7.2
adobeflash_player
8.0
adobeflash_player
8.0
adobeflash_player
8.0
adobeflash_player
8.0.24.0
adobeflash_player
8.0.34.0
adobeflash_player
8.0.35.0
adobeflash_player
8.0.39.0
adobeflash_player
9.0
adobeflash_player
9.0.16
adobeflash_player
9.0.18d60:d60
adobeflash_player
9.0.20
adobeflash_player
9.0.20.0
adobeflash_player
9.0.28
adobeflash_player
9.0.28.0
adobeflash_player
9.0.31
adobeflash_player
9.0.31.0
adobeflash_player
9.0.45.0
adobeflash_player
9.0.47.0
adobeflash_player
9.0.112.0
adobeflash_player
9.0.114.0
adobeflash_player
9.0.115.0
adobeflash_player
9.0.124.0
adobeflash_player
9.0.155.0
adobeflash_player
9.0.159.0
adobeflash_player
9.125.0
adobeflash_player
10.0.0.584
adobeflash_player
10.0.12.10
adobeflash_player
10.0.12.36
adobeflash_player
10.0.22.87
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
flashplugin-nonfree
lucid
not-affected
karmic
Fixed 10.0.42.34ubuntu0.9.10.1
released
jaunty
Fixed 10.0.42.34ubuntu0.9.04.1
released
intrepid
Fixed 10.0.42.34ubuntu0.8.10.1
released
hardy
Fixed 0.0.1.218+really9.0.260.0ubuntu1
released
dapper
ignored
References