← All CVEs

CVE-2009-0520

high · 9.3

Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."

9.3
CVSS
28.5%
EPSS (exploit prob.)
98th
EPSS percentile
2009-02-26
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
adobeair1.5
adobeflash_player<= 10.0.12.36
adobeflash_player7.0
adobeflash_player7.0.1
adobeflash_player7.0.25
adobeflash_player7.0.63
adobeflash_player7.0.63
adobeflash_player7.0.69.0
adobeflash_player7.0.70.0
adobeflash_player7.1
adobeflash_player7.1.1
adobeflash_player7.2
adobeflash_player8.0
adobeflash_player8.0
adobeflash_player8.0
adobeflash_player8.0.24.0
adobeflash_player8.0.34.0
adobeflash_player8.0.35.0
adobeflash_player8.0.39.0
adobeflash_player9.0.16
adobeflash_player9.0.20
adobeflash_player9.0.20.0
adobeflash_player9.0.28
adobeflash_player9.0.28.0
adobeflash_player9.0.31.0
adobeflash_player9.0.45.0
adobeflash_player9.0.47.0
adobeflash_player9.0.48.0
adobeflash_player9.0.112.0
adobeflash_player9.0.114.0
adobeflash_player9.0.115.0
adobeflash_player9.0.124.0
adobeflash_player10.0.0.584
adobeflash_player10.0.12.10
adobeflash_playercs3
adobeflash_playercs4
adobeflash_player_for_linux<= 10.0.15.3
adobeflex3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-0520