First published: Wed Aug 11 2010(Updated: )
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "click-jacking" issue.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR SDK | ||
Adobe AIR SDK | =1.0 | |
Adobe AIR SDK | =1.0.1 | |
Adobe AIR SDK | =1.5 | |
Adobe AIR SDK | =1.5.1 | |
Adobe AIR SDK | =1.5.3 | |
Adobe AIR SDK | =1.5.3.9120 | |
Adobe Acrobat Reader | ||
Adobe Acrobat Reader | <=10.1.53.64 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0.1 | |
Adobe Acrobat Reader | =7.0.25 | |
Adobe Acrobat Reader | =7.0.63 | |
Adobe Acrobat Reader | =7.1.1 | |
Adobe Acrobat Reader | =7.2 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.0.22.0 | |
Adobe Acrobat Reader | =8.0.33.0 | |
Adobe Acrobat Reader | =8.0.34.0 | |
Adobe Acrobat Reader | =8.0.35.0 | |
Adobe Acrobat Reader | =8.0.39.0 | |
Adobe Acrobat Reader | =8.0.42.0 | |
Adobe Acrobat Reader | =9.0 | |
Adobe Acrobat Reader | =9.0.16 | |
Adobe Acrobat Reader | =9.0.18d60 | |
Adobe Acrobat Reader | =9.0.20 | |
Adobe Acrobat Reader | =9.0.20.0 | |
Adobe Acrobat Reader | =9.0.28 | |
Adobe Acrobat Reader | =9.0.28.0 | |
Adobe Acrobat Reader | =9.0.31 | |
Adobe Acrobat Reader | =9.0.31.0 | |
Adobe Acrobat Reader | =9.0.45.0 | |
Adobe Acrobat Reader | =9.0.47.0 | |
Adobe Acrobat Reader | =9.0.48.0 | |
Adobe Acrobat Reader | =9.0.112.0 | |
Adobe Acrobat Reader | =9.0.114.0 | |
Adobe Acrobat Reader | =9.0.115.0 | |
Adobe Acrobat Reader | =9.0.124.0 | |
Adobe Acrobat Reader | =9.0.125.0 | |
Adobe Acrobat Reader | =9.0.151.0 | |
Adobe Acrobat Reader | =9.0.152.0 | |
Adobe Acrobat Reader | =9.0.159.0 | |
Adobe Acrobat Reader | =9.0.246.0 | |
Adobe Acrobat Reader | =9.0.260.0 | |
Adobe Acrobat Reader | =9.125.0 | |
Adobe Acrobat Reader | =10.0.0.584 | |
Adobe Acrobat Reader | =10.0.12.10 | |
Adobe Acrobat Reader | =10.0.12.36 | |
Adobe Acrobat Reader | =10.0.15.3 | |
Adobe Acrobat Reader | =10.0.22.87 | |
Adobe Acrobat Reader | =10.0.32.18 | |
Adobe Acrobat Reader | =10.0.42.34 | |
Adobe Acrobat Reader | =10.0.45.2 | |
Adobe Acrobat Reader | =10.1.52.14.1 | |
Adobe Acrobat Reader | =10.1.52.15 | |
Adobe Flash Player | =9.0.31 | |
Adobe Flash Player | =9.0.48.0 | |
Adobe Flash Player | =9.0.115.0 | |
Adobe Flash Player | =9.0.124.0 | |
Adobe Flash Player | =9.0.151.0 | |
Adobe Flash Player | =10.0.12.36 | |
Adobe Flash Player | =10.0.15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2215 has a moderate severity level due to its potential for clickjacking attacks.
To fix CVE-2010-2215, update Adobe Flash Player or Adobe AIR to the latest versions available at the time.
CVE-2010-2215 affects various versions of Adobe Flash Player and Adobe AIR prior to specific updates.
Yes, CVE-2010-2215 can be exploited remotely through crafted web pages designed to trick users.
Exploitation of CVE-2010-2215 can lead to unauthorized actions being carried out on behalf of the user, such as clicking links without consent.