Unrated severityNVD Advisory· Published Jul 31, 2009· Updated Apr 23, 2026
CVE-2009-1868
CVE-2009-1868
Description
Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing.
Affected products
40cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=1.5.1
- cpe:2.3:a:adobe:air:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:air:1.01:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:air:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:air:1.5:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 33 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=10.0.22.87
- cpe:2.3:a:adobe:flash_player:10.0.0.584:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:10.0.12.10:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:10.0.12.36:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.0.25:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.0.63:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.0.63:*:linux:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.0.69.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.0.70.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:7.2:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:8.0.24.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:8.0.34.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:8.0.35.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:8.0.39.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:8.0:*:basic:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:8.0:*:pro:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.112.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.114.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.115.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.124.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.20:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.20.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.28:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.28.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.31.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.45.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.47.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:9.0.48.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flex:3.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
19- www.adobe.com/support/security/bulletins/apsb09-10.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/35890nvdPatch
- www.securityfocus.com/bid/35902nvdPatch
- www.vupen.com/english/advisories/2009/2086nvdPatchVendor Advisory
- lists.apple.com/archives/security-announce/2009/Sep/msg00003.htmlnvd
- lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlnvd
- osvdb.org/56776nvd
- secunia.com/advisories/36193nvd
- secunia.com/advisories/36374nvd
- secunia.com/advisories/36701nvd
- security.gentoo.org/glsa/glsa-200908-04.xmlnvd
- sunsolve.sun.com/search/document.donvd
- support.apple.com/kb/HT3864nvd
- support.apple.com/kb/HT3865nvd
- www.adobe.com/support/security/bulletins/apsb09-13.htmlnvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/52185nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15955nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6865nvd
News mentions
0No linked articles in our index yet.