{
  "id": "CVE-2011-0609",
  "url": "https://spydr.io/cve/CVE-2011-0609",
  "published": "2011-03-15T17:55:03.827Z",
  "modified": "2026-06-16T23:27:44.460Z",
  "score": 7.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.63507,
  "epss_percentile": 0.99194,
  "exploited": true,
  "kev": {
    "added": "2022-06-08",
    "due": "2022-06-22",
    "action": "The impacted product is end-of-life and should be disconnected if still in use.",
    "ransomware": "Unknown",
    "name": "Adobe Flash Player Unspecified Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2011-0609"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "adobe",
    "opensuse",
    "suse",
    "google"
  ],
  "products": [
    "adobe flash player",
    "adobe acrobat",
    "adobe acrobat reader",
    "adobe air",
    "opensuse",
    "suse linux enterprise",
    "google chrome"
  ],
  "cwes": [],
  "description": "Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.html",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates_15.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://secunia.com/advisories/43751",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/43757",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/43772",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/43856",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://securityreason.com/securityalert/8152",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.adobe.com/support/security/advisories/apsa11-01.html",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://www.adobe.com/support/security/bulletins/apsb11-06.html",
      "tags": [
        "Not Applicable"
      ]
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/192052",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ]
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2011-0372.html",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/46860",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securitytracker.com/id?1025210",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securitytracker.com/id?1025211",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securitytracker.com/id?1025238",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0655",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0656",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0688",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0732",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66078",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14147",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-0609",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2011-0609",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
