HIGH
Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors
Published Dec 10, 2009
7.1
HIGHCVSS 2.0
EPSS 3.81%
Description
Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.
Affected products
No data.
AND
OR
- ≤ 1.5.2
- 1.0
- 1.0.1
- 1.1
- 1.5.1
- ≤ 10.0.32.18
- 7.0
- 7.0.1
- 7.0.25
- 7.0.63
- 7.0.69.0
- 7.0.70.0
- 7.1
- 7.1.1
- 7.2
- 8
- 8
- 8.0
- 8.0
- 8.0
- 8.0.24.0
- 8.0.34.0
- 8.0.35.0
- 8.0.39.0
- 9.0
- 9.0.16
- 9.0.18d60
- 9.0.20
- 9.0.20.0
- 9.0.28
- 9.0.28.0
- 9.0.31
- 9.0.31.0
- 9.0.45.0
- 9.0.47.0
- 9.0.48.0
- 9.0.112.0
- 9.0.114.0
- 9.0.115.0
- 9.0.124.0
- 9.0.155.0
- 9.0.159.0
- 9.125.0
- 10.0.0.584
- 10.0.12.10
- 10.0.12.36
- 10.0.22.87
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/60891 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/37584 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/37902 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/38241 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1023307 vdb-entryx_refsource_SECTRACKPatch
- http://support.apple.com/kb/HT4004 x_refsource_CONFIRM
- http://www.adobe.com/support/security/bulletins/apsb09-19.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/bid/37199 vdb-entryx_refsource_BID
- http://www.us-cert.gov/cas/techalerts/TA09-343A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2009/3456 vdb-entryx_refsource_VUPENPatchVendor Advisory
- http://www.vupen.com/english/advisories/2010/0173 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54637 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6663 vdb-entrysignaturex_refsource_OVAL
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Dec 10, 2009
Updated Aug 7, 2024
Reserved Nov 16, 2009
Link CVE-2009-3951
CISA Vulnrichment
Updated n/a