First published: Fri Jul 31 2009(Updated: )
Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe | =1.01 | |
Adobe | <=1.5.1 | |
Macromedia Flash Player | =9.0.48.0 | |
Macromedia Flash Player | =8.0.24.0 | |
Adobe | =1.5 | |
Adobe | =1.0 | |
Macromedia Flash Player | =7.1.1 | |
Macromedia Flash Player | =9.0.124.0 | |
Macromedia Flash Player | =9.0.47.0 | |
Macromedia Flash Player | =7.0.63 | |
Macromedia Flash Player | =7.0.70.0 | |
Macromedia Flash Player | =10.0.12.36 | |
Macromedia Flash Player | =8.0.35.0 | |
Macromedia Flash Player | =9.0.114.0 | |
Macromedia Flash Player | =8.0 | |
Adobe | =1.1 | |
Macromedia Flash Player | =9.0.20.0 | |
Macromedia Flash Player | =9.0.31.0 | |
Macromedia Flash Player | =9.0.112.0 | |
Macromedia Flash Player | =9.0.16 | |
Macromedia Flash Player | =10.0.0.584 | |
Macromedia Flash Player | =9.0.28.0 | |
Macromedia Flash Player | <=10.0.22.87 | |
Macromedia Flash Player | =7.0.69.0 | |
Macromedia Flash Player | =9.0.28 | |
Macromedia Flash Player | =9.0.45.0 | |
Adobe Flex | =3.0 | |
Macromedia Flash Player | =7.0 | |
Macromedia Flash Player | =7.2 | |
Macromedia Flash Player | =9.0.115.0 | |
Macromedia Flash Player | =7.0.25 | |
Macromedia Flash Player | =8.0 | |
Macromedia Flash Player | =8.0.39.0 | |
Macromedia Flash Player | =8.0.34.0 | |
Macromedia Flash Player | =7.1 | |
Macromedia Flash Player | =10.0.12.10 | |
Macromedia Flash Player | =9.0.20 | |
Macromedia Flash Player | =7.0.1 | |
Macromedia Flash Player | =7.0.63 | |
Macromedia Flash Player | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1864 has a high severity rating due to its potential for causing application crashes and executing arbitrary code.
To mitigate CVE-2009-1864, update Adobe Flash Player and Adobe AIR to versions that are not vulnerable, as specified in the security bulletins.
CVE-2009-1864 affects Adobe Flash Player versions before 9.0.246.0 and 10.x before 10.0.32.18, as well as Adobe AIR versions before 1.5.2.
Exploiting CVE-2009-1864 can lead to denial of service attacks or the execution of arbitrary code on the affected systems.
Currently, users are advised to upgrade to secure versions of Adobe Flash Player and AIR as the most effective workaround for CVE-2009-1864.