CVE-2009-3951

Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
adobeadobe_air
𝑥
≤ 1.5.2
adobeadobe_air
1.0
adobeadobe_air
1.0.1
adobeadobe_air
1.1
adobeadobe_air
1.5.1
adobeflash_player
𝑥
≤ 10.0.32.18
adobeflash_player
7.0
adobeflash_player
7.0.1
adobeflash_player
7.0.25
adobeflash_player
7.0.63
adobeflash_player
7.0.69.0
adobeflash_player
7.0.70.0
adobeflash_player
7.1
adobeflash_player
7.1.1
adobeflash_player
7.2
adobeflash_player
8.0
adobeflash_player
8.0
adobeflash_player
8.0
adobeflash_player
8.0.24.0
adobeflash_player
8.0.34.0
adobeflash_player
8.0.35.0
adobeflash_player
8.0.39.0
adobeflash_player
9.0
adobeflash_player
9.0.16
adobeflash_player
9.0.18d60:d60
adobeflash_player
9.0.20
adobeflash_player
9.0.20.0
adobeflash_player
9.0.28
adobeflash_player
9.0.28.0
adobeflash_player
9.0.31
adobeflash_player
9.0.31.0
adobeflash_player
9.0.45.0
adobeflash_player
9.0.47.0
adobeflash_player
9.0.48.0
adobeflash_player
9.0.112.0
adobeflash_player
9.0.114.0
adobeflash_player
9.0.115.0
adobeflash_player
9.0.124.0
adobeflash_player
9.0.155.0
adobeflash_player
9.0.159.0
adobeflash_player
9.125.0
adobeflash_player
10.0.0.584
adobeflash_player
10.0.12.10
adobeflash_player
10.0.12.36
adobeflash_player
10.0.22.87
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
flash-player
suse enterprise desktop 12
11.2.202.406-1.3
fixed
suse enterprise desktop 12 SP1
11.2.202.548-111.1
fixed
suse enterprise sap 12
11.2.202.406-1.3
fixed
suse enterprise sap 12 SP1
11.2.202.548-111.1
fixed
suse enterprise server 12
11.2.202.406-1.3
fixed
suse enterprise server 12 SP1
11.2.202.548-111.1
fixed
suse enterprise workstation 12
11.2.202.406-1.3
fixed
suse enterprise workstation 12 SP1
11.2.202.548-111.1
fixed
flash-player-gnome
suse enterprise desktop 12
11.2.202.406-1.3
fixed
suse enterprise desktop 12 SP1
11.2.202.548-111.1
fixed
suse enterprise sap 12
11.2.202.406-1.3
fixed
suse enterprise sap 12 SP1
11.2.202.548-111.1
fixed
suse enterprise server 12
11.2.202.406-1.3
fixed
suse enterprise server 12 SP1
11.2.202.548-111.1
fixed
suse enterprise workstation 12
11.2.202.406-1.3
fixed
suse enterprise workstation 12 SP1
11.2.202.548-111.1
fixed