CVE-2010-0186

Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
adobeadobe_air
𝑥
≤ 1.5.3.9120
adobeadobe_air
1.0
adobeadobe_air
1.1
adobeadobe_air
1.5.1
adobeadobe_air
1.5.2
adobeadobe_air
1.5.3
adobeflash_player
𝑥
≤ 10.0.42.34
adobeflash_player
6.0.21.0
adobeflash_player
6.0.79
adobeflash_player
7.0
adobeflash_player
7.0.1
adobeflash_player
7.0.25
adobeflash_player
7.0.63
adobeflash_player
7.0.69.0
adobeflash_player
7.0.70.0
adobeflash_player
7.1
adobeflash_player
7.1.1
adobeflash_player
7.2
adobeflash_player
8.0
adobeflash_player
8.0.22.0
adobeflash_player
8.0.24.0
adobeflash_player
8.0.33.0
adobeflash_player
8.0.34.0
adobeflash_player
8.0.35.0
adobeflash_player
8.0.39.0
adobeflash_player
8.0.42.0
adobeflash_player
9.0
adobeflash_player
9.0.16
adobeflash_player
9.0.18d60:d60
adobeflash_player
9.0.20
adobeflash_player
9.0.20.0
adobeflash_player
9.0.28.0
adobeflash_player
9.0.31
adobeflash_player
9.0.31.0
adobeflash_player
9.0.45.0
adobeflash_player
9.0.47.0
adobeflash_player
9.0.48.0
adobeflash_player
9.0.112.0
adobeflash_player
9.0.114.0
adobeflash_player
9.0.115.0
adobeflash_player
9.0.124.0
adobeflash_player
9.0.125.0
adobeflash_player
9.0.151.0
adobeflash_player
9.0.152.0
adobeflash_player
9.0.159.0
adobeflash_player
9.0.246.0
adobeflash_player
9.0.260.0
adobeflash_player
9.125.0
adobeflash_player
10.0.12.10
adobeflash_player
10.0.12.36
adobeflash_player
10.0.15.3
adobeflash_player
10.0.22.87
adobeflash_player
10.0.32.18
adobeacrobat
𝑥
≤ 9.3
adobeacrobat
8.0
adobeacrobat
8.1
adobeacrobat
8.1.1
adobeacrobat
8.1.2
adobeacrobat
8.1.3
adobeacrobat
8.1.4
adobeacrobat
8.1.5
adobeacrobat
8.1.6
adobeacrobat
8.1.7
adobeacrobat
9.0
adobeacrobat
9.1
adobeacrobat
9.1.1
adobeacrobat
9.1.2
adobeacrobat
9.1.3
adobeacrobat
9.2
adobeacrobat_reader
𝑥
≤ 9.3
adobeacrobat_reader
8.0
adobeacrobat_reader
8.1
adobeacrobat_reader
8.1.1
adobeacrobat_reader
8.1.2
adobeacrobat_reader
8.1.4
adobeacrobat_reader
8.1.5
adobeacrobat_reader
8.1.6
adobeacrobat_reader
8.1.7
adobeacrobat_reader
9.0
adobeacrobat_reader
9.1
adobeacrobat_reader
9.1.1
adobeacrobat_reader
9.1.2
adobeacrobat_reader
9.1.3
adobeacrobat_reader
9.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
dapper
dne
hardy
Fixed 10.0.45.2-1
released
intrepid
Fixed 10.0.45.2-1intrepid1
released
jaunty
Fixed 10.0.45.2-1jaunty1
released
karmic
Fixed 10.0.45.2-1karmic1
released
flashplugin-nonfree
dapper
ignored
hardy
Fixed 10.0.1.218+really9.0.262.0ubuntu1
released
intrepid
Fixed 10.0.45.2ubuntu0.8.10.1
released
jaunty
Fixed 10.0.45.2ubuntu0.9.04.1
released
karmic
Fixed 10.0.45.2ubuntu0.9.10.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
flash-player
suse enterprise desktop 12
11.2.202.406-1.3
fixed
suse enterprise desktop 12 SP1
11.2.202.548-111.1
fixed
suse enterprise sap 12
11.2.202.406-1.3
fixed
suse enterprise sap 12 SP1
11.2.202.548-111.1
fixed
suse enterprise server 12
11.2.202.406-1.3
fixed
suse enterprise server 12 SP1
11.2.202.548-111.1
fixed
suse enterprise workstation 12
11.2.202.406-1.3
fixed
suse enterprise workstation 12 SP1
11.2.202.548-111.1
fixed
flash-player-gnome
suse enterprise desktop 12
11.2.202.406-1.3
fixed
suse enterprise desktop 12 SP1
11.2.202.548-111.1
fixed
suse enterprise sap 12
11.2.202.406-1.3
fixed
suse enterprise sap 12 SP1
11.2.202.548-111.1
fixed
suse enterprise server 12
11.2.202.406-1.3
fixed
suse enterprise server 12 SP1
11.2.202.548-111.1
fixed
suse enterprise workstation 12
11.2.202.406-1.3
fixed
suse enterprise workstation 12 SP1
11.2.202.548-111.1
fixed
References