Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Mar 21, 2012 | Oct 14, 2008 |
| Apple Osx Flashplayerplugin | — | Upgrade macOS to the latest versionApply OS X security update 2010-007 | Dec 16, 2011 | Oct 14, 2008 |
| Freebsd | — | Upgrade linux-flashpluginUpgrade linux-f10-flashpluginUpgrade linux-f8-flashplugin | Dec 10, 2025 | Jun 14, 2010 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Oct 14, 2008 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Oct 14, 2008 |
| Suse | — | Upgrade flash-playerUpgrade flash-player-gnome | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | Oct 14, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub