Lucene search

K
nessusTenable5256.PRM
HistoryDec 09, 2009 - 12:00 a.m.

Adobe AIR < 1.5.3 Multiple Vulnerabilities (APSB09-19)

2009-12-0900:00:00
Tenable
www.tenable.com
14

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.727

Percentile

98.2%

The remote Windows host contains a version of Adobe AIR player that is earlier than 1.5.3. Such versions are reportedly affected by multiple vulnerabilities :

  • A vulnerability in the parsing of JPEG data that could potentially lead to code execution. (CVE-2009-3794)

  • A data injection vulnerability that could potentially lead to code execution. (CVE-2009-3796)

  • A memory corruption vulnerability that could potentially lead to code execution. (CVE-2009-3797)

  • A memory corruption vulnerability that could potentially lead to code execution. (CVE-2009-3798)

  • An integer overflow vulnerability that could potentially lead to code execution. (CVE-2009-3799)

  • Multiple crash vulnerabilities that could potentially lead to code execution. (CVE-2009-3800)

  • A Windows-only local file name access vulnerability in the Flash Player ActiveX control that could potentially lead to information disclosure. (CVE-2009-3951)

Binary data 5256.prm
VendorProductVersionCPE
adobeadobe_aircpe:/a:adobe:adobe_air

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.727

Percentile

98.2%