CVE-2009-0520
Last modified
CVE-2009-0520 is a vulnerability of currently unknown severity. Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue.". EPSS estimates a 28.48% chance of exploitation in the next 30 days.
Description
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Air | 1.5 |
| Adobe | Flash Player | <= 10.0.12.36 |
| Adobe | Flash Player | 7.0 |
| Adobe | Flash Player | 7.0.1 |
| Adobe | Flash Player | 7.0.25 |
| Adobe | Flash Player | 7.0.63 |
| Adobe | Flash Player | 7.0.69.0 |
| Adobe | Flash Player | 7.0.70.0 |
| Adobe | Flash Player | 7.1 |
| Adobe | Flash Player | 7.1.1 |
| Adobe | Flash Player | 7.2 |
| Adobe | Flash Player | 8.0 |
| Adobe | Flash Player | 8.0.24.0 |
| Adobe | Flash Player | 8.0.34.0 |
| Adobe | Flash Player | 8.0.35.0 |
| Adobe | Flash Player | 8.0.39.0 |
| Adobe | Flash Player | 9.0.16 |
| Adobe | Flash Player | 9.0.20 |
| Adobe | Flash Player | 9.0.20.0 |
| Adobe | Flash Player | 9.0.28 |
| Adobe | Flash Player | 9.0.28.0 |
| Adobe | Flash Player | 9.0.31.0 |
| Adobe | Flash Player | 9.0.45.0 |
| Adobe | Flash Player | 9.0.47.0 |
| Adobe | Flash Player | 9.0.48.0 |
| Adobe | Flash Player | 9.0.112.0 |
| Adobe | Flash Player | 9.0.114.0 |
| Adobe | Flash Player | 9.0.115.0 |
| Adobe | Flash Player | 9.0.124.0 |
| Adobe | Flash Player | 10.0.0.584 |
| Adobe | Flash Player | 10.0.12.10 |
| Adobe | Flash Player | cs3 |
| Adobe | Flash Player | cs4 |
| Adobe | Flash Player For Linux | <= 10.0.15.3 |
| Adobe | Flex | 3.0 |
References
- http://www.adobe.com/support/security/bulletins/apsb09-01.htmlPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlUS Government Resource
- http://www.adobe.com/support/security/bulletins/apsb09-01.htmlPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0520?
How severe is CVE-2009-0520?
How do I fix CVE-2009-0520?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0514Multiple directory traversal vulnerabilities in WebFrame 0.7…
- CVE-2009-0515Directory traversal vulnerability in check_lang.php in Yet A…
- CVE-2009-0516SQL injection vulnerability in the classified page (classifi…
- CVE-2009-0517Eval injection vulnerability in index.php in phpSlash 0.8.1.…
- CVE-2009-0518VI Client in VMware VirtualCenter before 2.5 Update 4, VMwar…
- CVE-2009-0519Unspecified vulnerability in Adobe Flash Player 9.x before 9…
- CVE-2009-0521Untrusted search path vulnerability in Adobe Flash Player 9.…
- CVE-2009-0522Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0…
- CVE-2009-0523Cross-site scripting (XSS) vulnerability in Adobe RoboHelp S…
- CVE-2009-0524Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6…
- CVE-2009-0525Cross-site scripting (XSS) vulnerability in the sajax_get_co…
- CVE-2009-0526Multiple cross-site scripting (XSS) vulnerabilities in index…
Are you affected by CVE-2009-0520?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
