CVE-2009-3794Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe AIR

Severity
9.3CRITICALNVD
EPSS
21.2%
top 4.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 10
Latest updateMay 2

Description

Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDadobe/flash_player10.0.32.18+37
NVDadobe/adobe_air1.5.2+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rxh4-4wmm-564x: Heap-based buffer overflow in Adobe Flash Player before 102022-05-02
CVEList
CVE-2009-3794: Heap-based buffer overflow in Adobe Flash Player before 102009-12-10

📋Vendor Advisories

6
Red Hat
flash-plugin: multiple code execution flaws (APSB09-19) (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800)2009-12-08
Red Hat
flash-plugin: multiple code execution flaws (APSB09-19) (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800)2009-12-08
Red Hat
flash-plugin: multiple code execution flaws (APSB09-19) (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800)2009-12-08
Red Hat
flash-plugin: multiple code execution flaws (APSB09-19) (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800)2009-12-08
Red Hat
flash-plugin: multiple code execution flaws (APSB09-19) (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800)2009-12-08

💬Community

1
Bugzilla
flash-plugin: multiple code execution flaws (APSB09-19) (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800)2009-12-03
CVE-2009-3794 — Adobe AIR vulnerability | cvebase