CVE-2009-0521
Last modified
CVE-2009-0521 is a vulnerability of currently unknown severity. Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player For Linux | <= 10.0.15.3 |
| Adobe | Flash Player For Linux | 10.0.12.36 |
References
- http://isc.sans.org/diary.html?storyid=5929Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2009-0332.htmlThird Party Advisory
- http://secunia.com/advisories/34012Broken Link
- http://secunia.com/advisories/34226Broken Link
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb09-01.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0513Broken Link, Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=487144Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48904Third Party Advisory, VDB Entry
- http://isc.sans.org/diary.html?storyid=5929Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2009-0332.htmlThird Party Advisory
- http://secunia.com/advisories/34012Broken Link
- http://secunia.com/advisories/34226Broken Link
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb09-01.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0513Broken Link, Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=487144Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48904Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0521?
How severe is CVE-2009-0521?
How do I fix CVE-2009-0521?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0515Directory traversal vulnerability in check_lang.php in Yet A…
- CVE-2009-0516SQL injection vulnerability in the classified page (classifi…
- CVE-2009-0517Eval injection vulnerability in index.php in phpSlash 0.8.1.…
- CVE-2009-0518VI Client in VMware VirtualCenter before 2.5 Update 4, VMwar…
- CVE-2009-0519Unspecified vulnerability in Adobe Flash Player 9.x before 9…
- CVE-2009-0520Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0…
- CVE-2009-0522Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0…
- CVE-2009-0523Cross-site scripting (XSS) vulnerability in Adobe RoboHelp S…
- CVE-2009-0524Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6…
- CVE-2009-0525Cross-site scripting (XSS) vulnerability in the sajax_get_co…
- CVE-2009-0526Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2009-0527PHP remote file inclusion vulnerability in plugins/rss_impor…
Are you affected by CVE-2009-0521?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
