Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Jun 19, 2012 | Nov 17, 2008 |
| Adobe Flash Apsb08 22 | — | Upgrade to Adobe Flash Player version 10.0.12.36 for Mac OS XUpgrade to Adobe Flash Player version 10.0.12.36 for LinuxUpgrade to Adobe Flash Player version 10.0.12.36 for Windows | Jul 11, 2013 | Nov 17, 2008 |
| Apple Osx Flashplayerplugin | — | Apply OS X security update 2008-008Upgrade macOS to the latest version | Dec 16, 2011 | Nov 17, 2008 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Nov 17, 2008 |
| Suse | — | Upgrade suse-releaseUpgrade flash-player | Dec 12, 2013 | Nov 17, 2008 |
| Ubuntu | — | Upgrade flashplugin-nonfree | Nov 19, 2024 | Nov 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub