CVE-2010-2179

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, when Firefox or Chrome is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to URL parsing.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
adobeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
adobeflash_player
𝑥
< 9.0.277.0
adobeflash_player
10.0.0.0 ≤
𝑥
< 10.1.53.64
adobeair
𝑥
< 2.0.2.12610
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
lucid
Fixed 10.1.53.64-1lucid1
released
karmic
Fixed 10.1.53.64-1karmic1
released
jaunty
Fixed 10.1.53.64-1jaunty1
released
hardy
Fixed 10.1.53.64-1
released
dapper
dne
flashplugin-nonfree
lucid
Fixed 10.1.53.64ubuntu0.10.04.1
released
karmic
Fixed 10.1.53.64ubuntu0.9.10.1
released
jaunty
Fixed 10.1.53.64ubuntu0.9.04.1
released
hardy
Fixed 10.0.1.218+really9.0.277.0ubuntu1
released
dapper
ignored
References