Lucene search

K
cveMitreCVE-2009-1869
HistoryJul 31, 2009 - 7:30 p.m.

CVE-2009-1869

2009-07-3119:30:00
CWE-189
mitre
web.nvd.nist.gov
43
cve-2009-1869
adobe flash player
avm2
integer overflow
denial of service
remote code execution
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.478

Percentile

97.5%

Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2 file with a large intrf_count value that triggers a dereference of an out-of-bounds pointer.

Affected configurations

Nvd
Node
adobeairRangeโ‰ค1.5.1
OR
adobeairMatch1.0
OR
adobeairMatch1.01
OR
adobeairMatch1.1
OR
adobeairMatch1.5
OR
adobeflash_playerRangeโ‰ค10.0.22.87
OR
adobeflash_playerMatch7.0
OR
adobeflash_playerMatch7.0.1
OR
adobeflash_playerMatch7.0.25
OR
adobeflash_playerMatch7.0.63
OR
adobeflash_playerMatch7.0.63linux
OR
adobeflash_playerMatch7.0.69.0
OR
adobeflash_playerMatch7.0.70.0
OR
adobeflash_playerMatch7.1
OR
adobeflash_playerMatch7.1.1
OR
adobeflash_playerMatch7.2
OR
adobeflash_playerMatch8.0
OR
adobeflash_playerMatch8.0basic
OR
adobeflash_playerMatch8.0pro
OR
adobeflash_playerMatch8.0.24.0
OR
adobeflash_playerMatch8.0.34.0
OR
adobeflash_playerMatch8.0.35.0
OR
adobeflash_playerMatch8.0.39.0
OR
adobeflash_playerMatch9.0.16
OR
adobeflash_playerMatch9.0.20
OR
adobeflash_playerMatch9.0.20.0
OR
adobeflash_playerMatch9.0.28
OR
adobeflash_playerMatch9.0.28.0
OR
adobeflash_playerMatch9.0.31.0
OR
adobeflash_playerMatch9.0.45.0
OR
adobeflash_playerMatch9.0.47.0
OR
adobeflash_playerMatch9.0.48.0
OR
adobeflash_playerMatch9.0.112.0
OR
adobeflash_playerMatch9.0.114.0
OR
adobeflash_playerMatch9.0.115.0
OR
adobeflash_playerMatch9.0.124.0
OR
adobeflash_playerMatch10.0.0.584
OR
adobeflash_playerMatch10.0.12.10
OR
adobeflash_playerMatch10.0.12.36
OR
adobeflexMatch3.0
VendorProductVersionCPE
adobeair*cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*
adobeair1.0cpe:2.3:a:adobe:air:1.0:*:*:*:*:*:*:*
adobeair1.01cpe:2.3:a:adobe:air:1.01:*:*:*:*:*:*:*
adobeair1.1cpe:2.3:a:adobe:air:1.1:*:*:*:*:*:*:*
adobeair1.5cpe:2.3:a:adobe:air:1.5:*:*:*:*:*:*:*
adobeflash_player*cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
adobeflash_player7.0cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:*
adobeflash_player7.0.1cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:*
adobeflash_player7.0.25cpe:2.3:a:adobe:flash_player:7.0.25:*:*:*:*:*:*:*
adobeflash_player7.0.63cpe:2.3:a:adobe:flash_player:7.0.63:*:*:*:*:*:*:*
Rows per page:
1-10 of 401

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.478

Percentile

97.5%