Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Mar 21, 2012 | Dec 10, 2009 |
| Apple Osx Flashplayerplugin | — | Apply OS X security update 2010-001 | Dec 16, 2011 | Dec 10, 2009 |
| Freebsd | — | Upgrade linux-f10-flashpluginUpgrade linux-flashpluginUpgrade linux-f8-flashplugin | Dec 10, 2025 | Dec 9, 2009 |
| Suse | — | Upgrade flash-player-gnomeUpgrade flash-player | Feb 17, 2015 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub