Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Mar 21, 2012 | Dec 10, 2009 |
| Adobe Flash Apsb09 19 | — | Upgrade to Adobe Flash Player version 10.0.42.34 for Mac OS XUpgrade to Adobe Flash Player version 10.0.42.34 for WindowsUpgrade to Adobe Flash Player version 10.0.42.34 for Linux | Jul 11, 2013 | Dec 10, 2009 |
| Apple Osx Flashplayerplugin | — | Apply OS X security update 2010-001 | Dec 16, 2011 | Dec 10, 2009 |
| Freebsd | — | Upgrade linux-f10-flashpluginUpgrade linux-flashpluginUpgrade linux-f8-flashplugin | Dec 10, 2025 | Dec 9, 2009 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Dec 10, 2009 |
| Suse | — | Upgrade flash-playerUpgrade flash-player-gnome | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade flashplugin-nonfree | Nov 19, 2024 | Dec 10, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub