CVE-2009-1870

Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to obtain sensitive information via vectors involving saving an SWF file to a hard drive, related to a "local sandbox vulnerability."
References
Link Resource
http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html
http://osvdb.org/56778
http://secunia.com/advisories/36193
http://secunia.com/advisories/36374
http://secunia.com/advisories/36701
http://security.gentoo.org/glsa/glsa-200908-04.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1
http://support.apple.com/kb/HT3864
http://support.apple.com/kb/HT3865
http://www.adobe.com/support/security/bulletins/apsb09-10.html Patch Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb09-13.html
http://www.securityfocus.com/bid/35890 Patch
http://www.securityfocus.com/bid/35908 Patch
http://www.securitytracker.com/id?1022629
http://www.vupen.com/english/advisories/2009/2086 Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/52180
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15887
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6648
http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html
http://osvdb.org/56778
http://secunia.com/advisories/36193
http://secunia.com/advisories/36374
http://secunia.com/advisories/36701
http://security.gentoo.org/glsa/glsa-200908-04.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1
http://support.apple.com/kb/HT3864
http://support.apple.com/kb/HT3865
http://www.adobe.com/support/security/bulletins/apsb09-10.html Patch Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb09-13.html
http://www.securityfocus.com/bid/35890 Patch
http://www.securityfocus.com/bid/35908 Patch
http://www.securitytracker.com/id?1022629
http://www.vupen.com/english/advisories/2009/2086 Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/52180
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15887
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6648
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:air:1.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:air:1.01:*:*:*:*:*:*:*
cpe:2.3:a:adobe:air:1.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:air:1.5:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.25:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.63:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.63:*:linux:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.69.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.70.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.2:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0:*:basic:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0:*:pro:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.24.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.34.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.35.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.39.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.16:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.20:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.20.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.31.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.45.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.47.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.48.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.112.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.114.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.115.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.124.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:10.0.0.584:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:10.0.12.10:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:10.0.12.36:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flex:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:03

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html - () http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html -
References () http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html - () http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html -
References () http://osvdb.org/56778 - () http://osvdb.org/56778 -
References () http://secunia.com/advisories/36193 - () http://secunia.com/advisories/36193 -
References () http://secunia.com/advisories/36374 - () http://secunia.com/advisories/36374 -
References () http://secunia.com/advisories/36701 - () http://secunia.com/advisories/36701 -
References () http://security.gentoo.org/glsa/glsa-200908-04.xml - () http://security.gentoo.org/glsa/glsa-200908-04.xml -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 -
References () http://support.apple.com/kb/HT3864 - () http://support.apple.com/kb/HT3864 -
References () http://support.apple.com/kb/HT3865 - () http://support.apple.com/kb/HT3865 -
References () http://www.adobe.com/support/security/bulletins/apsb09-10.html - Patch, Vendor Advisory () http://www.adobe.com/support/security/bulletins/apsb09-10.html - Patch, Vendor Advisory
References () http://www.adobe.com/support/security/bulletins/apsb09-13.html - () http://www.adobe.com/support/security/bulletins/apsb09-13.html -
References () http://www.securityfocus.com/bid/35890 - Patch () http://www.securityfocus.com/bid/35890 - Patch
References () http://www.securityfocus.com/bid/35908 - Patch () http://www.securityfocus.com/bid/35908 - Patch
References () http://www.securitytracker.com/id?1022629 - () http://www.securitytracker.com/id?1022629 -
References () http://www.vupen.com/english/advisories/2009/2086 - Patch, Vendor Advisory () http://www.vupen.com/english/advisories/2009/2086 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/52180 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/52180 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15887 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15887 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6648 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6648 -

Information

Published : 2009-07-31 19:30

Updated : 2024-11-21 01:03


NVD link : CVE-2009-1870

Mitre link : CVE-2009-1870

CVE.ORG link : CVE-2009-1870


JSON object : View

Products Affected

adobe

  • air
  • flash_player
  • flex
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor