
CVE-2009-0520 – Adobe Flash Player 9/10 - Invalid Object Reference Remote Code Execution
https://notcve.org/view.php?id=CVE-2009-0520
26 Feb 2009 — Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue." Adobe Flash Player v9.x anteriores a v9.0.159.0 y 10.x before 10.0.22.87 no elimina apropiadamente referencias a objetos destruidos durante el procesado de un archivo Shockwave Flash, lo que permite a los atacantes remotos ejecutar ar... • https://www.exploit-db.com/exploits/32811 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2009-0521 – flash-plugin: Linux-specific information disclosure (privilege escalation)
https://notcve.org/view.php?id=CVE-2009-0521
26 Feb 2009 — Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH. Vulnerabilidad de ruta de búsqueda no confiable en Adobe Flash Player 9v.x anteriores a v9.0.159.0 y v10.x anteriores a 10.0.22.87 en Linux que permite a los usuarios locales obtener información sensible o obtener privilegios a través de una librería manipulada en u... • http://isc.sans.org/diary.html?storyid=5929 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2009-0522
https://notcve.org/view.php?id=CVE-2009-0522
26 Feb 2009 — Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related to a "Clickjacking attack." Adobe Flash Player 9.x antes de la 9.0.159.0 y 10.x antes de la 10.0.22.87 sobre Windows permite a atacantes remotos engañar a un usuario para que visite una URL arbitraria a través de una manipulación no especificada de la "pantalla el puntero del ratón", relaci... • http://isc.sans.org/diary.html?storyid=5929 •

CVE-2009-0114
https://notcve.org/view.php?id=CVE-2009-0114
26 Feb 2009 — Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant." Una vulnerabilidad no especificada en Administrador de configuración de Adobe Flash Player 9.x antes de 9.0.159.0, 10.x antes de 10.0.22.87 y, posiblemente otras versiones, permite a atacantes remotos engañar a un usu... • http://isc.sans.org/diary.html?storyid=5929 •

CVE-2008-5499 – Adobe Flash Player - ActionScript Launch Command Execution
https://notcve.org/view.php?id=CVE-2008-5499
18 Dec 2008 — Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file. Vulnerabilidad sin especificar en Adobe Flash Player para Linux v10.0.12.36, y v9.0.151.0 y versiones anteriores, permite a atacantes remotos ejecutar código de su elección a través de un fichero SWF manipulado. • https://www.exploit-db.com/exploits/18761 • CWE-94: Improper Control of Generation of Code ('Code Injection') •