Lucene search

K
cve[email protected]CVE-2009-3797
HistoryDec 10, 2009 - 7:30 p.m.

CVE-2009-3797

2009-12-1019:30:00
CWE-399
web.nvd.nist.gov
28
cve-2009-3797
adobe flash player
adobe air
memory corruption
vulnerability
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.4%

Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.

Affected configurations

NVD
Node
adobeadobe_airRange1.5.2
OR
adobeadobe_airMatch1.0
OR
adobeadobe_airMatch1.0.1
OR
adobeadobe_airMatch1.1
OR
adobeadobe_airMatch1.5.1
OR
adobeflash_playerMatch10.0.0.584
OR
adobeflash_playerMatch10.0.12.10
OR
adobeflash_playerMatch10.0.12.36
OR
adobeflash_playerMatch10.0.22.87
OR
adobeflash_playerMatch10.0.32.18

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.4%