CVE-2009-1862

U

nspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.

References
Link Resource
http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html Broken Link Vendor Advisory
http://bugs.adobe.com/jira/browse/FP-1265 Broken Link
http://isc.sans.org/diary.html?storyid=6847 Not Applicable
http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html Mailing List Third Party Advisory
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html Mailing List Third Party Advisory
http://news.cnet.com/8301-27080_3-10293389-245.html Broken Link
http://secunia.com/advisories/36193 Broken Link
http://secunia.com/advisories/36374 Broken Link
http://secunia.com/advisories/36701 Broken Link
http://security.gentoo.org/glsa/glsa-200908-04.xml Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 Broken Link
http://support.apple.com/kb/HT3864 Third Party Advisory
http://support.apple.com/kb/HT3865 Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa09-03.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb09-10.html Not Applicable
http://www.adobe.com/support/security/bulletins/apsb09-13.html Not Applicable
http://www.kb.cert.org/vuls/id/259425 Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/35759 Broken Link Third Party Advisory VDB Entry
http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99 Broken Link
http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability Broken Link
http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html Broken Link Vendor Advisory
http://bugs.adobe.com/jira/browse/FP-1265 Broken Link
http://isc.sans.org/diary.html?storyid=6847 Not Applicable
http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html Mailing List Third Party Advisory
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html Mailing List Third Party Advisory
http://news.cnet.com/8301-27080_3-10293389-245.html Broken Link
http://secunia.com/advisories/36193 Broken Link
http://secunia.com/advisories/36374 Broken Link
http://secunia.com/advisories/36701 Broken Link
http://security.gentoo.org/glsa/glsa-200908-04.xml Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 Broken Link
http://support.apple.com/kb/HT3864 Third Party Advisory
http://support.apple.com/kb/HT3865 Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa09-03.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb09-10.html Not Applicable
http://www.adobe.com/support/security/bulletins/apsb09-13.html Not Applicable
http://www.kb.cert.org/vuls/id/259425 Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/35759 Broken Link Third Party Advisory VDB Entry
http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99 Broken Link
http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-1862
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*

History

22 Oct 2025, 01:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-1862 -

21 Oct 2025, 20:15

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-1862', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-1862 -

21 Nov 2024, 01:03

Type Values Removed Values Added
References () http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html - Broken Link, Vendor Advisory () http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html - Broken Link, Vendor Advisory
References () http://bugs.adobe.com/jira/browse/FP-1265 - Broken Link () http://bugs.adobe.com/jira/browse/FP-1265 - Broken Link
References () http://isc.sans.org/diary.html?storyid=6847 - Not Applicable () http://isc.sans.org/diary.html?storyid=6847 - Not Applicable
References () http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html - Mailing List, Third Party Advisory () http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html - Mailing List, Third Party Advisory
References () http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html - Mailing List, Third Party Advisory () http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html - Mailing List, Third Party Advisory
References () http://news.cnet.com/8301-27080_3-10293389-245.html - Broken Link () http://news.cnet.com/8301-27080_3-10293389-245.html - Broken Link
References () http://secunia.com/advisories/36193 - Broken Link () http://secunia.com/advisories/36193 - Broken Link
References () http://secunia.com/advisories/36374 - Broken Link () http://secunia.com/advisories/36374 - Broken Link
References () http://secunia.com/advisories/36701 - Broken Link () http://secunia.com/advisories/36701 - Broken Link
References () http://security.gentoo.org/glsa/glsa-200908-04.xml - Third Party Advisory () http://security.gentoo.org/glsa/glsa-200908-04.xml - Third Party Advisory
References () http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 - Broken Link () http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 - Broken Link
References () http://support.apple.com/kb/HT3864 - Third Party Advisory () http://support.apple.com/kb/HT3864 - Third Party Advisory
References () http://support.apple.com/kb/HT3865 - Third Party Advisory () http://support.apple.com/kb/HT3865 - Third Party Advisory
References () http://www.adobe.com/support/security/advisories/apsa09-03.html - Vendor Advisory () http://www.adobe.com/support/security/advisories/apsa09-03.html - Vendor Advisory
References () http://www.adobe.com/support/security/bulletins/apsb09-10.html - Not Applicable () http://www.adobe.com/support/security/bulletins/apsb09-10.html - Not Applicable
References () http://www.adobe.com/support/security/bulletins/apsb09-13.html - Not Applicable () http://www.adobe.com/support/security/bulletins/apsb09-13.html - Not Applicable
References () http://www.kb.cert.org/vuls/id/259425 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/259425 - Third Party Advisory, US Government Resource
References () http://www.securityfocus.com/bid/35759 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/35759 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99 - Broken Link () http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99 - Broken Link
References () http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability - Broken Link () http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability - Broken Link

28 Jun 2024, 14:20

Type Values Removed Values Added
References () http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html - Vendor Advisory () http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html - Broken Link, Vendor Advisory
References () http://bugs.adobe.com/jira/browse/FP-1265 - () http://bugs.adobe.com/jira/browse/FP-1265 - Broken Link
References () http://isc.sans.org/diary.html?storyid=6847 - () http://isc.sans.org/diary.html?storyid=6847 - Not Applicable
References () http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html - () http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html - Mailing List, Third Party Advisory
References () http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html - () http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html - Mailing List, Third Party Advisory
References () http://news.cnet.com/8301-27080_3-10293389-245.html - () http://news.cnet.com/8301-27080_3-10293389-245.html - Broken Link
References () http://secunia.com/advisories/36193 - () http://secunia.com/advisories/36193 - Broken Link
References () http://secunia.com/advisories/36374 - () http://secunia.com/advisories/36374 - Broken Link
References () http://secunia.com/advisories/36701 - () http://secunia.com/advisories/36701 - Broken Link
References () http://security.gentoo.org/glsa/glsa-200908-04.xml - () http://security.gentoo.org/glsa/glsa-200908-04.xml - Third Party Advisory
References () http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 - Broken Link
References () http://support.apple.com/kb/HT3864 - () http://support.apple.com/kb/HT3864 - Third Party Advisory
References () http://support.apple.com/kb/HT3865 - () http://support.apple.com/kb/HT3865 - Third Party Advisory
References () http://www.adobe.com/support/security/advisories/apsa09-03.html - () http://www.adobe.com/support/security/advisories/apsa09-03.html - Vendor Advisory
References () http://www.adobe.com/support/security/bulletins/apsb09-10.html - () http://www.adobe.com/support/security/bulletins/apsb09-10.html - Not Applicable
References () http://www.adobe.com/support/security/bulletins/apsb09-13.html - () http://www.adobe.com/support/security/bulletins/apsb09-13.html - Not Applicable
References () http://www.kb.cert.org/vuls/id/259425 - US Government Resource () http://www.kb.cert.org/vuls/id/259425 - Third Party Advisory, US Government Resource
References () http://www.securityfocus.com/bid/35759 - () http://www.securityfocus.com/bid/35759 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99 - () http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99 - Broken Link
References () http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability - () http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability - Broken Link
CVSS v2 : 9.3
v3 : unknown
v2 : 9.3
v3 : 7.8
CPE cpe:2.3:a:adobe:acrobat_reader:9.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.31.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.115.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.159.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:10.0.22.87:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.31:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:9.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.112.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.48.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.16:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.20.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.155.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.45.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:10.0.12.10:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:10.0.0.584:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:9.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.125.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.124.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:9.1.2:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:10.0.12.36:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:9.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.47.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.114.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:9.1.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:9.1.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.20:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.18d60:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:9.1.2:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
CWE CWE-94 CWE-787

Information

Published : 2009-07-23 20:30

Updated : 2025-10-22 01:15


NVD link : CVE-2009-1862

Mitre link : CVE-2009-1862

CVE.ORG link : CVE-2009-1862


JSON object : View

CWE
CWE-787

Out-of-bounds Write