First published: Thu Feb 11 2010(Updated: )
Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/flash-plugin | <0:9.0.262.0-1.el3 | 0:9.0.262.0-1.el3 |
redhat/flash-plugin | <0:9.0.262.0-1.el4 | 0:9.0.262.0-1.el4 |
redhat/acroread | <0:9.3.1-1.el4 | 0:9.3.1-1.el4 |
redhat/flash-plugin | <0:10.0.45.2-1.el5 | 0:10.0.45.2-1.el5 |
redhat/acroread | <0:9.3.1-1.el5 | 0:9.3.1-1.el5 |
Adobe | <=1.5.3.9120 | |
Adobe | =1.0 | |
Adobe | =1.1 | |
Adobe | =1.5.1 | |
Adobe | =1.5.2 | |
Adobe | =1.5.3 | |
Macromedia Flash Player | <=10.0.42.34 | |
Macromedia Flash Player | =6.0.21.0 | |
Macromedia Flash Player | =6.0.79 | |
Macromedia Flash Player | =7.0 | |
Macromedia Flash Player | =7.0.1 | |
Macromedia Flash Player | =7.0.25 | |
Macromedia Flash Player | =7.0.63 | |
Macromedia Flash Player | =7.0.69.0 | |
Macromedia Flash Player | =7.0.70.0 | |
Macromedia Flash Player | =7.1 | |
Macromedia Flash Player | =7.1.1 | |
Macromedia Flash Player | =7.2 | |
Macromedia Flash Player | =8.0 | |
Macromedia Flash Player | =8.0.22.0 | |
Macromedia Flash Player | =8.0.24.0 | |
Macromedia Flash Player | =8.0.33.0 | |
Macromedia Flash Player | =8.0.34.0 | |
Macromedia Flash Player | =8.0.35.0 | |
Macromedia Flash Player | =8.0.39.0 | |
Macromedia Flash Player | =8.0.42.0 | |
Macromedia Flash Player | =9.0 | |
Macromedia Flash Player | =9.0.16 | |
Macromedia Flash Player | =9.0.18d60 | |
Macromedia Flash Player | =9.0.20 | |
Macromedia Flash Player | =9.0.20.0 | |
Macromedia Flash Player | =9.0.28.0 | |
Macromedia Flash Player | =9.0.31 | |
Macromedia Flash Player | =9.0.31.0 | |
Macromedia Flash Player | =9.0.45.0 | |
Macromedia Flash Player | =9.0.47.0 | |
Macromedia Flash Player | =9.0.48.0 | |
Macromedia Flash Player | =9.0.112.0 | |
Macromedia Flash Player | =9.0.114.0 | |
Macromedia Flash Player | =9.0.115.0 | |
Macromedia Flash Player | =9.0.124.0 | |
Macromedia Flash Player | =9.0.125.0 | |
Macromedia Flash Player | =9.0.151.0 | |
Macromedia Flash Player | =9.0.152.0 | |
Macromedia Flash Player | =9.0.159.0 | |
Macromedia Flash Player | =9.0.246.0 | |
Macromedia Flash Player | =9.0.260.0 | |
Macromedia Flash Player | =9.125.0 | |
Macromedia Flash Player | =10.0.12.10 | |
Macromedia Flash Player | =10.0.12.36 | |
Macromedia Flash Player | =10.0.15.3 | |
Macromedia Flash Player | =10.0.22.87 | |
Macromedia Flash Player | =10.0.32.18 | |
Adobe Acrobat Reader | <=9.3 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.1 | |
Adobe Acrobat Reader | =8.1.1 | |
Adobe Acrobat Reader | =8.1.2 | |
Adobe Acrobat Reader | =8.1.3 | |
Adobe Acrobat Reader | =8.1.4 | |
Adobe Acrobat Reader | =8.1.5 | |
Adobe Acrobat Reader | =8.1.6 | |
Adobe Acrobat Reader | =8.1.7 | |
Adobe Acrobat Reader | =9.0 | |
Adobe Acrobat Reader | =9.1 | |
Adobe Acrobat Reader | =9.1.1 | |
Adobe Acrobat Reader | =9.1.2 | |
Adobe Acrobat Reader | =9.1.3 | |
Adobe Acrobat Reader | =9.2 | |
Adobe Acrobat Reader Notification Manager | <=9.3 | |
Adobe Acrobat Reader Notification Manager | =8.0 | |
Adobe Acrobat Reader Notification Manager | =8.1 | |
Adobe Acrobat Reader Notification Manager | =8.1.1 | |
Adobe Acrobat Reader Notification Manager | =8.1.2 | |
Adobe Acrobat Reader Notification Manager | =8.1.4 | |
Adobe Acrobat Reader Notification Manager | =8.1.5 | |
Adobe Acrobat Reader Notification Manager | =8.1.6 | |
Adobe Acrobat Reader Notification Manager | =8.1.7 | |
Adobe Acrobat Reader Notification Manager | =9.0 | |
Adobe Acrobat Reader Notification Manager | =9.1 | |
Adobe Acrobat Reader Notification Manager | =9.1.1 | |
Adobe Acrobat Reader Notification Manager | =9.1.2 | |
Adobe Acrobat Reader Notification Manager | =9.1.3 | |
Adobe Acrobat Reader Notification Manager | =9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2010-0186 has been classified as a critical vulnerability, allowing cross-domain access and potential exploitation by attackers.
To fix CVE-2010-0186, upgrade your Adobe software to the latest versions listed in the security advisories.
CVE-2010-0186 affects Adobe Flash Player, Adobe AIR, and Adobe Reader versions prior to their respective patched releases.
Yes, CVE-2010-0186 can potentially allow attackers to bypass security restrictions and access sensitive data across domains.
The potential impacts of CVE-2010-0186 include unauthorized data access and exploitation of application functionality by malicious users.