CVE-2009-3797
Description
Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Memory corruption in Adobe Flash Player 10.x before 10.0.42.34 and AIR before 1.5.3 allows remote code execution via a crafted SWF file.
Vulnerability
CVE-2009-3797 is a memory corruption vulnerability in Adobe Flash Player 10.x prior to version 10.0.42.34 and Adobe AIR prior to version 1.5.3 [4]. The flaw is triggered by unspecified vectors, likely a specially crafted SWF file, when a user views the file in a browser or AIR application [4]. Affected versions include Flash Player 10.0.32.18 and earlier, and AIR 1.5.2 and earlier [4].
Exploitation
An attacker needs only to host a malicious SWF file on a website and convince a user to visit that site [4]. No authentication or special network position is required beyond the ability to serve the file. The user must interact by loading the SWF in a browser or AIR runtime, which triggers the memory corruption [4].
Impact
Successful exploitation allows an attacker to execute arbitrary code on the victim's system with the privileges of the user running Flash Player or AIR [4]. This can lead to full compromise of the affected system, including data theft, installation of malware, or further network propagation.
Mitigation
Adobe released Flash Player 10.0.42.34 and AIR 1.5.3 as part of Security Bulletin APSB09-19 to fix this vulnerability [4]. Users should update to these versions immediately. Workarounds include disabling the Flash plugin or using the NoScript extension to whitelist trusted sites [4]. Red Hat provided an update via RHSA-2009:1657 [2][3], and Apple included the fix in Security Update 2010-001 [1].
- About Security Update 2010-001 - Apple Support
- Support
- 543857 – (APSB09-19, CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800) flash-plugin: multiple code execution flaws (APSB09-19) (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800)
- Adobe Flash Vulnerabilities Affect Flash Player and Adobe AIR | CISA
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
10cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:*range: <=1.5.2
- cpe:2.3:a:adobe:adobe_air:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:adobe_air:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:adobe_air:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:adobe_air:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:10.0.0.584:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:adobe:flash_player:10.0.0.584:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:10.0.12.10:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:10.0.12.36:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:10.0.22.87:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:10.0.32.18:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
20- securitytracker.com/idnvdPatch
- securitytracker.com/idnvdPatch
- www.adobe.com/support/security/bulletins/apsb09-19.htmlnvdPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2009-1657.htmlnvdPatch
- www.vupen.com/english/advisories/2009/3456nvdPatchVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdPatch
- secunia.com/advisories/37584nvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA09-343A.htmlnvdUS Government Resource
- lists.apple.com/archives/security-announce/2010/Jan/msg00000.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.htmlnvd
- secunia.com/advisories/37902nvd
- secunia.com/advisories/38241nvd
- sunsolve.sun.com/search/document.donvd
- support.apple.com/kb/HT4004nvd
- www.securityfocus.com/bid/37199nvd
- www.vupen.com/english/advisories/2010/0173nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/54633nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15795nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7140nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8350nvd
News mentions
0No linked articles in our index yet.