CVE-2009-0522: Medium severity Adobe AIR vulnerability

Published Feb 26, 2009
·
Updated

Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related to a "Clickjacking attack."

Affected Software

78 affected components
Adobe AIR=1.5
Adobe Flash Player<=10.0.12.36
Adobe Flash Player=7.0
Adobe Flash Player=7.0.1
Adobe Flash Player=7.0.25
Adobe Flash Player=7.0.63
Adobe Flash Player=7.0.63
Adobe Flash Player=7.0.69.0
Adobe Flash Player=7.0.70.0
Adobe Flash Player=7.1
Adobe Flash Player=7.1.1
Adobe Flash Player=7.2
Adobe Flash Player=8.0
Adobe Flash Player=8.0
Adobe Flash Player=8.0
Adobe Flash Player=8.0.24.0
Adobe Flash Player=8.0.34.0
Adobe Flash Player=8.0.35.0
Adobe Flash Player=8.0.39.0
Adobe Flash Player=9.0.16
Adobe Flash Player=9.0.20
Adobe Flash Player=9.0.20.0
Adobe Flash Player=9.0.28
Adobe Flash Player=9.0.28.0
Adobe Flash Player=9.0.31.0
Adobe Flash Player=9.0.45.0
Adobe Flash Player=9.0.47.0
Adobe Flash Player=9.0.48.0
Adobe Flash Player=9.0.112.0
Adobe Flash Player=9.0.114.0
Adobe Flash Player=9.0.115.0
Adobe Flash Player=9.0.124.0
Adobe Flash Player=10.0.0.584
Adobe Flash Player=10.0.12.10
Adobe Flash Player=cs3
Adobe Flash Player=cs4
Adobe Flash Player for Linux<=10.0.15.3
Adobe Flex=3.0
Microsoft Windows
All of the following
Any of the following
Adobe AIR=1.5
Adobe Flash Player<=10.0.12.36
Adobe Flash Player=7.0
Adobe Flash Player=7.0.1
Adobe Flash Player=7.0.25
Adobe Flash Player=7.0.63
Adobe Flash Player=7.0.63
Adobe Flash Player=7.0.69.0
Adobe Flash Player=7.0.70.0
Adobe Flash Player=7.1
Adobe Flash Player=7.1.1
Adobe Flash Player=7.2
Adobe Flash Player=8.0
Adobe Flash Player=8.0
Adobe Flash Player=8.0
Adobe Flash Player=8.0.24.0
Adobe Flash Player=8.0.34.0
Adobe Flash Player=8.0.35.0
Adobe Flash Player=8.0.39.0
Adobe Flash Player=9.0.16
Adobe Flash Player=9.0.20
Adobe Flash Player=9.0.20.0
Adobe Flash Player=9.0.28
Adobe Flash Player=9.0.28.0
Adobe Flash Player=9.0.31.0
Adobe Flash Player=9.0.45.0
Adobe Flash Player=9.0.47.0
Adobe Flash Player=9.0.48.0
Adobe Flash Player=9.0.112.0
Adobe Flash Player=9.0.114.0
Adobe Flash Player=9.0.115.0
Adobe Flash Player=9.0.124.0
Adobe Flash Player=10.0.0.584
Adobe Flash Player=10.0.12.10
Adobe Flash Player=cs3
Adobe Flash Player=cs4
Adobe Flash Player for Linux<=10.0.15.3
Adobe Flex=3.0
Microsoft Windows

Event History

Feb 26, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
04:17 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2009-0522?

CVE-2009-0522 is considered a medium severity vulnerability.

2

How do I fix CVE-2009-0522?

To mitigate CVE-2009-0522, upgrade Adobe Flash Player to version 10.0.22.87 or later.

3

What software is affected by CVE-2009-0522?

CVE-2009-0522 affects Adobe Flash Player versions 9.x before 9.0.159.0 and 10.x before 10.0.22.87.

4

What type of attack does CVE-2009-0522 enable?

CVE-2009-0522 enables Clickjacking attacks, allowing attackers to manipulate mouse pointer display.

5

Can CVE-2009-0522 affect Windows users?

Yes, CVE-2009-0522 primarily affects Windows users running vulnerable versions of Adobe Flash Player.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203