First published: Fri Jul 31 2009(Updated: )
Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "clickjacking vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR | <=1.5.1 | |
Adobe AIR | =1.0 | |
Adobe AIR | =1.01 | |
Adobe AIR | =1.1 | |
Adobe AIR | =1.5 | |
Adobe Flash Player for Internet Explorer 11 | <=10.0.22.87 | |
Adobe Flash Player for Internet Explorer 11 | =7.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.1 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.25 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.63 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.63 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.69.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.70.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.1 | |
Adobe Flash Player for Internet Explorer 11 | =7.1.1 | |
Adobe Flash Player for Internet Explorer 11 | =7.2 | |
Adobe Flash Player for Internet Explorer 11 | =8.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.24.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.34.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.35.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.39.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.16 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.20 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.20.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.28 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.28.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.31.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.45.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.47.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.48.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.112.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.114.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.115.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.124.0 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.0.584 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.12.10 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.12.36 | |
Adobe Flex | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1867 has a moderate severity level due to its potential for clickjacking attacks.
To fix CVE-2009-1867, update Adobe Flash Player to version 10.0.32.18 or later and Adobe AIR to version 1.5.2 or later.
CVE-2009-1867 affects Adobe Flash Player versions before 9.0.246.0 and 10.x before 10.0.32.18, as well as Adobe AIR versions prior to 1.5.2.
CVE-2009-1867 is a clickjacking vulnerability that allows attackers to trick users into interacting with malicious content.
Users of affected versions of Adobe Flash Player and AIR are vulnerable to CVE-2009-1867 if they do not update to the latest protected versions.