Vulnerability Details CVE-2009-3799
Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.129
EPSS Ranking 93.7%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2009-3799
-
cpe:2.3:a:adobe:adobe_air:-
-
cpe:2.3:a:adobe:adobe_air:1.0
-
cpe:2.3:a:adobe:adobe_air:1.0.1
-
cpe:2.3:a:adobe:adobe_air:1.0.4990
-
cpe:2.3:a:adobe:adobe_air:1.0.8.4990
-
cpe:2.3:a:adobe:adobe_air:1.1
-
cpe:2.3:a:adobe:adobe_air:1.1.0.5790
-
cpe:2.3:a:adobe:adobe_air:1.5
-
cpe:2.3:a:adobe:adobe_air:1.5.0.7220
-
cpe:2.3:a:adobe:adobe_air:1.5.1
-
cpe:2.3:a:adobe:adobe_air:1.5.1.8210
-
cpe:2.3:a:adobe:adobe_air:1.5.2
-
cpe:2.3:a:adobe:flash_player:-
-
cpe:2.3:a:adobe:flash_player:10
-
cpe:2.3:a:adobe:flash_player:10.0.0.584
-
cpe:2.3:a:adobe:flash_player:10.0.12.10
-
cpe:2.3:a:adobe:flash_player:10.0.12.36
-
cpe:2.3:a:adobe:flash_player:10.0.15.3
-
cpe:2.3:a:adobe:flash_player:10.0.2.54
-
cpe:2.3:a:adobe:flash_player:10.0.22.87
-
cpe:2.3:a:adobe:flash_player:10.0.32.18
-
cpe:2.3:a:adobe:flash_player:2
-
cpe:2.3:a:adobe:flash_player:3
-
cpe:2.3:a:adobe:flash_player:4
-
cpe:2.3:a:adobe:flash_player:5
-
cpe:2.3:a:adobe:flash_player:6
-
cpe:2.3:a:adobe:flash_player:6.0.21.0
-
cpe:2.3:a:adobe:flash_player:6.0.79
-
cpe:2.3:a:adobe:flash_player:7
-
cpe:2.3:a:adobe:flash_player:7.0
-
cpe:2.3:a:adobe:flash_player:7.0.1
-
cpe:2.3:a:adobe:flash_player:7.0.14.0
-
cpe:2.3:a:adobe:flash_player:7.0.19.0
-
cpe:2.3:a:adobe:flash_player:7.0.24.0
-
cpe:2.3:a:adobe:flash_player:7.0.25
-
cpe:2.3:a:adobe:flash_player:7.0.53.0
-
cpe:2.3:a:adobe:flash_player:7.0.60.0
-
cpe:2.3:a:adobe:flash_player:7.0.61.0
-
cpe:2.3:a:adobe:flash_player:7.0.63
-
cpe:2.3:a:adobe:flash_player:7.0.66.0
-
cpe:2.3:a:adobe:flash_player:7.0.67.0
-
cpe:2.3:a:adobe:flash_player:7.0.68.0
-
cpe:2.3:a:adobe:flash_player:7.0.69.0
-
cpe:2.3:a:adobe:flash_player:7.0.70.0
-
cpe:2.3:a:adobe:flash_player:7.0.73.0
-
cpe:2.3:a:adobe:flash_player:7.1
-
cpe:2.3:a:adobe:flash_player:7.1.1
-
cpe:2.3:a:adobe:flash_player:7.2
-
cpe:2.3:a:adobe:flash_player:8
-
cpe:2.3:a:adobe:flash_player:8.0
-
cpe:2.3:a:adobe:flash_player:8.0.22.0
-
cpe:2.3:a:adobe:flash_player:8.0.24.0
-
cpe:2.3:a:adobe:flash_player:8.0.33.0
-
cpe:2.3:a:adobe:flash_player:8.0.34.0
-
cpe:2.3:a:adobe:flash_player:8.0.35.0
-
cpe:2.3:a:adobe:flash_player:8.0.39.0
-
cpe:2.3:a:adobe:flash_player:8.0.42.0
-
cpe:2.3:a:adobe:flash_player:9
-
cpe:2.3:a:adobe:flash_player:9.0
-
cpe:2.3:a:adobe:flash_player:9.0.112.0
-
cpe:2.3:a:adobe:flash_player:9.0.114.0
-
cpe:2.3:a:adobe:flash_player:9.0.115.0
-
cpe:2.3:a:adobe:flash_player:9.0.124.0
-
cpe:2.3:a:adobe:flash_player:9.0.125.0
-
cpe:2.3:a:adobe:flash_player:9.0.151.0
-
cpe:2.3:a:adobe:flash_player:9.0.152.0
-
cpe:2.3:a:adobe:flash_player:9.0.155.0
-
cpe:2.3:a:adobe:flash_player:9.0.159.0
-
cpe:2.3:a:adobe:flash_player:9.0.16
-
cpe:2.3:a:adobe:flash_player:9.0.16.0
-
cpe:2.3:a:adobe:flash_player:9.0.18d60
-
cpe:2.3:a:adobe:flash_player:9.0.20
-
cpe:2.3:a:adobe:flash_player:9.0.20.0
-
cpe:2.3:a:adobe:flash_player:9.0.246.0
-
cpe:2.3:a:adobe:flash_player:9.0.260.0
-
cpe:2.3:a:adobe:flash_player:9.0.262.0
-
cpe:2.3:a:adobe:flash_player:9.0.277.0
-
cpe:2.3:a:adobe:flash_player:9.0.28
-
cpe:2.3:a:adobe:flash_player:9.0.28.0
-
cpe:2.3:a:adobe:flash_player:9.0.280
-
cpe:2.3:a:adobe:flash_player:9.0.283.0
-
cpe:2.3:a:adobe:flash_player:9.0.289.0
-
cpe:2.3:a:adobe:flash_player:9.0.31
-
cpe:2.3:a:adobe:flash_player:9.0.31.0
-
cpe:2.3:a:adobe:flash_player:9.0.45.0
-
cpe:2.3:a:adobe:flash_player:9.0.47.0
-
cpe:2.3:a:adobe:flash_player:9.0.48.0
-
cpe:2.3:a:adobe:flash_player:9.0.8.0
-
cpe:2.3:a:adobe:flash_player:9.0.9.0
-
cpe:2.3:a:adobe:flash_player:9.125.0