9.3

CVE-2009-3794

Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Adobe Air Version <= 1.5.2
Adobe ≫ Adobe Air Version 1.0
Adobe ≫ Adobe Air Version 1.0.1
Adobe ≫ Adobe Air Version 1.1
Adobe ≫ Adobe Air Version 1.5.1
Adobe ≫ Flash Player Version <= 10.0.32.18
Adobe ≫ Flash Player Version 7.0
Adobe ≫ Flash Player Version 7.0.1
Adobe ≫ Flash Player Version 7.0.25
Adobe ≫ Flash Player Version 7.0.63
Adobe ≫ Flash Player Version 7.0.69.0
Adobe ≫ Flash Player Version 7.0.70.0
Adobe ≫ Flash Player Version 7.1
Adobe ≫ Flash Player Version 7.1.1
Adobe ≫ Flash Player Version 7.2
Adobe ≫ Flash Player Version 8 Edition pro
Adobe ≫ Flash Player Version 8 Edition professional
Adobe ≫ Flash Player Version 8.0
Adobe ≫ Flash Player Version 8.0 Edition basic
Adobe ≫ Flash Player Version 8.0 Edition pro
Adobe ≫ Flash Player Version 8.0.24.0
Adobe ≫ Flash Player Version 8.0.34.0
Adobe ≫ Flash Player Version 8.0.35.0
Adobe ≫ Flash Player Version 8.0.39.0
Adobe ≫ Flash Player Version 9.0
Adobe ≫ Flash Player Version 9.0.16
Adobe ≫ Flash Player Version 9.0.18d60
Adobe ≫ Flash Player Version 9.0.20
Adobe ≫ Flash Player Version 9.0.20.0
Adobe ≫ Flash Player Version 9.0.28
Adobe ≫ Flash Player Version 9.0.28.0
Adobe ≫ Flash Player Version 9.0.31
Adobe ≫ Flash Player Version 9.0.31.0
Adobe ≫ Flash Player Version 9.0.45.0
Adobe ≫ Flash Player Version 9.0.47.0
Adobe ≫ Flash Player Version 9.0.112.0
Adobe ≫ Flash Player Version 9.0.114.0
Adobe ≫ Flash Player Version 9.0.115.0
Adobe ≫ Flash Player Version 9.0.124.0
Adobe ≫ Flash Player Version 9.0.155.0
Adobe ≫ Flash Player Version 9.0.159.0
Adobe ≫ Flash Player Version 9.125.0
Adobe ≫ Flash Player Version 10.0.0.584
Adobe ≫ Flash Player Version 10.0.12.10
Adobe ≫ Flash Player Version 10.0.12.36
Adobe ≫ Flash Player Version 10.0.22.87
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.56% 0.955
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html
http://secunia.com/advisories/38241
http://support.apple.com/kb/HT4004
http://www.vupen.com/english/advisories/2010/0173
http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html
http://osvdb.org/60885
http://secunia.com/advisories/37584
Vendor Advisory
http://secunia.com/advisories/37902
http://securitytracker.com/id?1023306
http://securitytracker.com/id?1023307
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021716.1-1
http://www.adobe.com/support/security/bulletins/apsb09-19.html
Patch
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2009-1657.html
http://www.redhat.com/support/errata/RHSA-2009-1658.html
Patch
http://www.securityfocus.com/archive/1/508336/100/0/threaded
http://www.securityfocus.com/bid/37199
http://www.us-cert.gov/cas/techalerts/TA09-343A.html
US Government Resource
http://www.vupen.com/english/advisories/2009/3456
Patch
Vendor Advisory
http://zerodayinitiative.com/advisories/ZDI-09-092/
Patch
https://bugzilla.redhat.com/show_bug.cgi?id=543857
https://exchange.xforce.ibmcloud.com/vulnerabilities/54631
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15948
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7465
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8686