First published: Fri Jul 31 2009(Updated: )
Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe | <=1.5.1 | |
Adobe | =1.0 | |
Adobe | =1.01 | |
Adobe | =1.1 | |
Adobe | =1.5 | |
Macromedia Flash Player | <=10.0.22.87 | |
Macromedia Flash Player | =7.0 | |
Macromedia Flash Player | =7.0.1 | |
Macromedia Flash Player | =7.0.25 | |
Macromedia Flash Player | =7.0.63 | |
Macromedia Flash Player | =7.0.63 | |
Macromedia Flash Player | =7.0.69.0 | |
Macromedia Flash Player | =7.0.70.0 | |
Macromedia Flash Player | =7.1 | |
Macromedia Flash Player | =7.1.1 | |
Macromedia Flash Player | =7.2 | |
Macromedia Flash Player | =8.0 | |
Macromedia Flash Player | =8.0 | |
Macromedia Flash Player | =8.0 | |
Macromedia Flash Player | =8.0.24.0 | |
Macromedia Flash Player | =8.0.34.0 | |
Macromedia Flash Player | =8.0.35.0 | |
Macromedia Flash Player | =8.0.39.0 | |
Macromedia Flash Player | =9.0.16 | |
Macromedia Flash Player | =9.0.20 | |
Macromedia Flash Player | =9.0.20.0 | |
Macromedia Flash Player | =9.0.28 | |
Macromedia Flash Player | =9.0.28.0 | |
Macromedia Flash Player | =9.0.31.0 | |
Macromedia Flash Player | =9.0.45.0 | |
Macromedia Flash Player | =9.0.47.0 | |
Macromedia Flash Player | =9.0.48.0 | |
Macromedia Flash Player | =9.0.112.0 | |
Macromedia Flash Player | =9.0.114.0 | |
Macromedia Flash Player | =9.0.115.0 | |
Macromedia Flash Player | =9.0.124.0 | |
Macromedia Flash Player | =10.0.0.584 | |
Macromedia Flash Player | =10.0.12.10 | |
Macromedia Flash Player | =10.0.12.36 | |
Adobe Flex | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-1868 is critical due to the potential for remote code execution and denial of service.
To fix CVE-2009-1868, upgrade Adobe Flash Player to version 10.0.32.18 or later, or Adobe AIR to version 1.5.2 or later.
CVE-2009-1868 enables attackers to cause application crashes or may allow the execution of arbitrary code.
Adobe Flash Player versions before 10.0.32.18 and Adobe AIR versions before 1.5.2 are affected by CVE-2009-1868.
Yes, CVE-2009-1868 can be exploited remotely via unspecified vectors related to URL parsing.