CVE detail
CVE-2011-0609
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
Researchers at Symantec say a sophisticated backdoor Trojan known as Egobot is targeting confidential information from South Korean companies as well as corporation doing business with South Korea.
newswww.securityweek.comOct 15, 2013, 7:32 PM- Shielding targeted applicationsHelp Net Security
When we discuss exploit prevention, we often talk about “targeted applications.’ This term refers to end-user applications which can be exploited by hackers for malicious purposes. There are a few requirements that define these applications. They receive external content: In order to deliver the exploit, the attacker must be able to provide the user with specially crafted content that contains the malicious exploit (a.k.a. weaponized content). This can be for example an HTML web page … More →
newswww.helpnetsecurity.comAug 28, 2013, 8:00 AM “IXESHE” Attack Campaign Leveraged “Weaponized” PDFs Targeting Zero-day Exploits Dating Back to 2009. Trend Micro has revealed details on a series of attacks that tried to stay under the radar by using machines inside compromised networks as command and control (C&Cs) servers.
newswww.securityweek.comMay 29, 2012, 5:25 PMRSA has started providing more detail into the mid-March attack on its SecurID token-based authentication system, but to get a fuller story you have to be an RSA customer willing to sign a nondisclosure agreement (NDA). An NDA means that you agree to keep secret what RSA would be willing to tell you. Sources say […]
newswww.csoonline.comApr 5, 2011, 3:00 PM- The execution of the RSA hackHelp Net Security
More than two weeks have passed since the high profile RSA hack, and the company has finally decided to share some of the details regarding the attack. The question that is uppermost on most people’s minds – What information did the attacker manage to get their hands on? – still remains unanswered, but at least we now know how he managed to breach the company defenses. It all started with a malicious email, to which … More →
newswww.helpnetsecurity.comApr 4, 2011, 7:40 AM - Japan leakage analysis emails with malicious XLS attachmentsHelp Net Security
Japan’s seemingly unending series of misfortunes has so far generated a vast variety of online scams. The latest one includes spam emails containing Excel attachments rigged with Flash exploits. The subject line states: “Japan Nuclear Radiation Leakage and Vulnerability Analysis”, and the email is supposedly sent by the Office of Nuclear Security and Incident Response with the U.S. Nuclear Regulatory Commission. Given that lots of people are worried about the effects that the Fukushima reactor … More →
newswww.helpnetsecurity.comMar 24, 2011, 8:54 AM Adobe has issued a warning of a newly identified critical vulnerability in its Flash Player, and that the vulnerability is being exploited in targeted attacks via a Flash (.swf) file embedded in Microsoft Excel (.xls) files delivered via email.
newswww.securityweek.comMar 15, 2011, 12:52 PM- Critical vulnerability in Adobe Flash PlayerHelp Net Security
A critical vulnerability exists in Adobe Flash Player 10.2.152.33 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems (Adobe Flash Player 10.2.154.18 and earlier for Chrome users), Adobe Flash Player 10.1.106.16 and earlier versions for Android, and the authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems. This vulnerability (CVE-2011-0609) could cause a crash and potentially allow an attacker … More →
newswww.helpnetsecurity.comMar 15, 2011, 6:53 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2011-0611CVSS 8.8 · High
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLi…
- CVE-2014-0497CVSS 9.8 · Critical
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote att…
- CVE-2012-0725CVSS 9.3 · Critical
Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other im…
- CVE-2012-0724CVSS 9.3 · Critical
Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other im…
- CVE-2010-3654CVSS 9.3 · Critical
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or liba…
- CVE-2016-0959CVSS 9.8 · Critical
Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google…