CVE-2009-0521
published 2009-02-26CVE-2009-0521: Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive…
PriorityP413medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
1.05%
60.5th percentile
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player_for_linux | <= 10.0.15.3 | — |
| adobe | flash_player_for_linux | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h35j-98vm-989g: Untrusted search path vulnerability in Adobe Flash Player 9
ghsa_unreviewed·2022-05-02
CVE-2009-0521 [MEDIUM] CWE-200 GHSA-h35j-98vm-989g: Untrusted search path vulnerability in Adobe Flash Player 9
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.
Red Hat
flash-plugin: Linux-specific information disclosure (privilege escalation)
vendor_redhat·2009-02-24·CVSS 4.6
CVE-2009-0521 [MEDIUM] flash-plugin: Linux-specific information disclosure (privilege escalation)
flash-plugin: Linux-specific information disclosure (privilege escalation)
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.
No detection rules found.
No public exploits indexed.
http://isc.sans.org/diary.html?storyid=5929http://rhn.redhat.com/errata/RHSA-2009-0332.htmlhttp://secunia.com/advisories/34012http://secunia.com/advisories/34226http://security.gentoo.org/glsa/glsa-200903-23.xmlhttp://www.adobe.com/support/security/bulletins/apsb09-01.htmlhttp://www.vupen.com/english/advisories/2009/0513https://bugzilla.redhat.com/show_bug.cgi?id=487144https://exchange.xforce.ibmcloud.com/vulnerabilities/48904https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6160http://isc.sans.org/diary.html?storyid=5929http://rhn.redhat.com/errata/RHSA-2009-0332.htmlhttp://secunia.com/advisories/34012http://secunia.com/advisories/34226http://security.gentoo.org/glsa/glsa-200903-23.xmlhttp://www.adobe.com/support/security/bulletins/apsb09-01.htmlhttp://www.vupen.com/english/advisories/2009/0513https://bugzilla.redhat.com/show_bug.cgi?id=487144https://exchange.xforce.ibmcloud.com/vulnerabilities/48904https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6160
2009-02-26
Published