Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.
Vector
NETWORK
Complexity
MEDIUM
Authentication
NONE
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE
Adobe Flash Player 9.0.114.0
Adobe Flash Player 9.0.112.0
Adobe Flash Player 9.0.48.0
Adobe Flash Player 9.0.47.0
Adobe Flash Player 9.0.45.0
Adobe Flash Player 9.0.31.0
Adobe Flash Player 9.0.31
Adobe Flash Player 9.0.28.0
Adobe Flash Player 9.0.28
Adobe Flash Player 9.0.20.0
Adobe Flash Player 9.0.20
Adobe Flash player 9.0.16.0 (not an official CPE)
Adobe Flash Player 9.0.18d60
Adobe Flash Player 9.0.16
Adobe Flash Player 9.0.289.0
Adobe Flash Player 9.0.8.0
Adobe Flash Player 9.0
Adobe Flash Player 9.0.115.0