Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Mar 21, 2012 | Feb 15, 2010 |
| Adobe Reader Apsb10 07 | — | — | Apr 12, 2012 | Feb 15, 2010 |
| Apple Osx Flashplayerplugin | — | Apply OS X security update 2010-004Upgrade macOS to the latest version | Dec 16, 2011 | Feb 15, 2010 |
| Freebsd | — | Upgrade linux-f8-flashpluginUpgrade linux-flashpluginUpgrade linux-f10-flashplugin | Dec 10, 2025 | Feb 13, 2010 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash.Upgrade app-text/acroread. | Oct 30, 2017 | Feb 15, 2010 |
| Suse | — | Upgrade flash-player-gnomeUpgrade flash-player | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | Feb 15, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub