CVE-2010-2215
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
4.3
Description
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "click-jacking" issue.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| adobe | adobe_air | | |
| adobe | adobe_air | 1.0 | |
| adobe | adobe_air | 1.0.1 | |
| adobe | adobe_air | 1.5 | |
| adobe | adobe_air | 1.5.1 | |
| adobe | adobe_air | 1.5.3 | |
| adobe | adobe_air | 1.5.3.9120 | |
| adobe | flash_player | | |
| adobe | flash_player | 7.0 | |
| adobe | flash_player | 7.0.1 | |
| adobe | flash_player | 7.0.25 | |
| adobe | flash_player | 7.0.63 | |
| adobe | flash_player | 7.1.1 | |
| adobe | flash_player | 7.2 | |
| adobe | flash_player | 8.0 | |
| adobe | flash_player | 8.0.22.0 | |
| adobe | flash_player | 8.0.33.0 | |
| adobe | flash_player | 8.0.34.0 | |
| adobe | flash_player | 8.0.35.0 | |
| adobe | flash_player | 8.0.39.0 | |
| adobe | flash_player | 8.0.42.0 | |
| adobe | flash_player | 9.0 | |
| adobe | flash_player | 9.0.16 | |
| adobe | flash_player | 9.0.18d60 | |
| adobe | flash_player | 9.0.20 | |
| adobe | flash_player | 9.0.20.0 | |
| adobe | flash_player | 9.0.28 | |
| adobe | flash_player | 9.0.28.0 | |
| adobe | flash_player | 9.0.31 | |
| adobe | flash_player | 9.0.31.0 | |
| adobe | flash_player | 9.0.45.0 | |
| adobe | flash_player | 9.0.47.0 | |
| adobe | flash_player | 9.0.48.0 | |
| adobe | flash_player | 9.0.112.0 | |
| adobe | flash_player | 9.0.114.0 | |
| adobe | flash_player | 9.0.115.0 | |
| adobe | flash_player | 9.0.124.0 | |
| adobe | flash_player | 9.0.125.0 | |
| adobe | flash_player | 9.0.151.0 | |
| adobe | flash_player | 9.0.152.0 | |
| adobe | flash_player | 9.0.159.0 | |
| adobe | flash_player | 9.0.246.0 | |
| adobe | flash_player | 9.0.260.0 | |
| adobe | flash_player | 9.125.0 | |
| adobe | flash_player | 10.0.0.584 | |
| adobe | flash_player | 10.0.12.10 | |
| adobe | flash_player | 10.0.12.36 | |
| adobe | flash_player | 10.0.15.3 | |
| adobe | flash_player | 10.0.22.87 | |
| adobe | flash_player | 10.0.32.18 | |
| adobe | flash_player | 10.0.42.34 | |
| adobe | flash_player | 10.0.45.2 | |
| adobe | flash_player | 10.1.52.14.1 | |
| adobe | flash_player | 10.1.52.15 | |
| adobe | flash_player_for_linux | 9.0.31 | |
| adobe | flash_player_for_linux | 9.0.48.0 | |
| adobe | flash_player_for_linux | 9.0.115.0 | |
| adobe | flash_player_for_linux | 9.0.124.0 | |
| adobe | flash_player_for_linux | 9.0.151.0 | |
| adobe | flash_player_for_linux | 10.0.12.36 | |
| adobe | flash_player_for_linux | 10.0.15.3 | |
References
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
- http://marc.info/?l=bugtraq&m=128767780602751&w=2
- http://secunia.com/advisories/43026
- http://security.gentoo.org/glsa/glsa-201101-09.xml
- http://support.apple.com/kb/HT4435
- http://www.adobe.com/support/security/bulletins/apsb10-16.html
- http://www.securityfocus.com/bid/42361
- http://www.securitytracker.com/id?1024621
- http://www.vupen.com/english/advisories/2011/0192
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11532
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16192
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
- http://marc.info/?l=bugtraq&m=128767780602751&w=2
- http://secunia.com/advisories/43026
- http://security.gentoo.org/glsa/glsa-201101-09.xml
- http://support.apple.com/kb/HT4435
- http://www.adobe.com/support/security/bulletins/apsb10-16.html
- http://www.securityfocus.com/bid/42361
- http://www.securitytracker.com/id?1024621
- http://www.vupen.com/english/advisories/2011/0192
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11532
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16192
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.