CVE-2009-1868
Adobe AIR < 1.5.2 - Heap-Based Buffer Overflow via URL Parsing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1868. PoCs published by iDefense.
AI-analyzed exploit summary This exploit leverages a heap-based buffer overflow in Adobe Flash Player and Adobe AIR to execute arbitrary code. The PoC involves a crafted HTML file that embeds a malicious SWF file with an overflowed parameter, triggering the vulnerability.
Description
Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing.
Exploits (1)
This exploit leverages a heap-based buffer overflow in Adobe Flash Player and Adobe AIR to execute arbitrary code. The PoC involves a crafted HTML file that embeds a malicious SWF file with an overflowed parameter, triggering the vulnerability.