VYPR
High severity7.8CISA KEVNVD Advisory· Published Mar 15, 2011· Updated Apr 21, 2026

CVE-2011-0609

CVE-2011-0609

Description

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.

Affected products

14
  • cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*range: >=9.0,<=9.4.2
    • cpe:2.3:a:adobe:acrobat:10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:10.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*range: >=9.0,<=9.4.2
    • cpe:2.3:a:adobe:acrobat_reader:10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:10.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*
    Range: <=2.5.1
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
    Range: <=10.2.154.13
  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
    Range: <10.0.648.134
  • OpenSUSE/openSUSE3 versions
    cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise:10.0:sp3:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:suse:linux_enterprise:10.0:sp3:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise:11.0:sp1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

23

News mentions

0

No linked articles in our index yet.