Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Mar 21, 2012 | Jul 23, 2009 |
| Adobe Reader Apsb09 10 | — | — | Apr 12, 2012 | Jul 23, 2009 |
| Apple Osx Flashplayerplugin | — | Upgrade macOS to the latest version | Dec 16, 2011 | Jul 23, 2009 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash.Upgrade app-text/acroread. | Oct 30, 2017 | Jul 23, 2009 |
| Suse | — | Upgrade flash-player | Feb 17, 2015 | Jul 23, 2009 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Jul 23, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub