Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-1862 | First vendor Publication | 2009-07-23 |
Vendor | Cve | Last vendor Modification | 2025-02-10 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 7.8 | ||
Base Score | 7.8 | Environmental Score | 7.8 |
impact SubScore | 5.9 | Temporal Score | 7.8 |
Exploitabality Sub Score | 1.8 | ||
Attack Vector | Local | Attack Complexity | Low |
Privileges Required | None | User Interaction | Required |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1862 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-787 | Out-of-bounds Write (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
Adobe Flash Player authplay.dll vulnerability | More info here |
OpenVAS Exploits
Date | Description |
---|---|
2010-05-12 | Name : Mac OS X Security Update 2009-005 File : nvt/macosx_secupd_2009-005.nasl |
2010-05-12 | Name : Mac OS X 10.6.1 Update File : nvt/macosx_upd_10_6_1.nasl |
2009-08-17 | Name : RedHat Security Advisory RHSA-2009:1188 File : nvt/RHSA_2009_1188.nasl |
2009-08-17 | Name : RedHat Security Advisory RHSA-2009:1189 File : nvt/RHSA_2009_1189.nasl |
2009-08-17 | Name : Gentoo Security Advisory GLSA 200908-04 (adobe-flash acroread) File : nvt/glsa_200908_04.nasl |
2009-07-29 | Name : Adobe Products '.pdf' and '.swf' Code Execution Vulnerability - July09 (Linux) File : nvt/secpod_adobe_prdts_code_exec_vuln_jul09_lin.nasl |
2009-07-29 | Name : Adobe Products '.pdf' and '.swf' Code Execution Vulnerability - July09 (Win) File : nvt/secpod_adobe_prdts_code_exec_vuln_jul09_win.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
56282 | Adobe Multiple Products Flash Handling Unspecified Arbitrary Code Execution |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Adobe Flash Player remote code execution attempt RuleID : 28661 - Revision : 5 - Type : FILE-FLASH |
2014-01-10 | Adobe Flash Player remote code execution attempt RuleID : 28660 - Revision : 5 - Type : FILE-FLASH |
2014-01-10 | attempted download of a PDF with embedded Flash over pop3 RuleID : 19280 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over pop3 RuleID : 19279 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over pop3 RuleID : 19278 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over pop3 RuleID : 19277 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over pop3 RuleID : 19276 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over pop3 RuleID : 19275 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over smtp RuleID : 19274 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over smtp RuleID : 19273 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over smtp RuleID : 19272 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over smtp RuleID : 19271 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash over smtp RuleID : 19270 - Revision : 4 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash RuleID : 19269 - Revision : 14 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash RuleID : 19268 - Revision : 14 - Type : FILE-PDF |
2014-01-10 | Possible Adobe Flash Player ActionScript byte_array heap spray attempt RuleID : 15729 - Revision : 14 - Type : FILE-FLASH |
2014-01-10 | Possible Adobe Acrobat Reader ActionScript byte_array heap spray attempt RuleID : 15728 - Revision : 15 - Type : FILE-PDF |
2014-01-10 | attempted download of a PDF with embedded Flash RuleID : 15727 - Revision : 27 - Type : FILE-PDF |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-01-24 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2009-1188.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2009-1189.nasl - Type : ACT_GATHER_INFO |
2011-01-27 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_flash-player-6386.nasl - Type : ACT_GATHER_INFO |
2009-10-06 | Name : The remote openSUSE host is missing a security update. File : suse_flash-player-6387.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 11 host is missing a security update. File : suse_11_flash-player-090731.nasl - Type : ACT_GATHER_INFO |
2009-09-11 | Name : The remote host is missing a Mac OS X update that fixes various security issues. File : macosx_10_6_1.nasl - Type : ACT_GATHER_INFO |
2009-09-11 | Name : The remote host is missing a Mac OS X update that fixes various security issues. File : macosx_SecUpd2009-005.nasl - Type : ACT_GATHER_INFO |
2009-08-28 | Name : The version of Adobe Acrobat on the remote Windows host is affected by a memo... File : adobe_acrobat_913.nasl - Type : ACT_GATHER_INFO |
2009-08-10 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200908-04.nasl - Type : ACT_GATHER_INFO |
2009-08-05 | Name : The PDF file viewer on the remote Windows host is affected by a memory corrup... File : adobe_reader_913.nasl - Type : ACT_GATHER_INFO |
2009-08-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_flash-player-090731.nasl - Type : ACT_GATHER_INFO |
2009-08-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_flash-player-090731.nasl - Type : ACT_GATHER_INFO |
2009-07-31 | Name : The remote Windows host contains a version of Adobe AIR that is affected by m... File : adobe_air_apsb09-10.nasl - Type : ACT_GATHER_INFO |
2009-07-30 | Name : The remote Windows host contains a browser plugin that is affected by multipl... File : flash_player_apsb09_10.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2025-02-11 17:21:38 |
|
2024-12-19 21:21:26 |
|
2024-11-28 23:10:48 |
|
2024-11-28 12:19:05 |
|
2024-10-12 01:11:23 |
|
2024-09-06 01:10:59 |
|
2024-07-20 01:10:31 |
|
2024-06-28 21:28:01 |
|
2021-05-04 12:09:38 |
|
2021-04-22 01:09:59 |
|
2020-05-23 00:23:51 |
|
2016-04-26 18:51:54 |
|
2014-02-17 10:50:15 |
|
2014-01-19 21:25:56 |
|
2013-05-10 23:51:35 |
|