CVE-2011-2139

Adobe Flash Player <10.3.183.5-10.3.186.3 - CSRF

Title source: llm
STIX 2.1

Description

Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.

References (9)

Core 9
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48308
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA11-222A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16030
Patch, Vendor Advisory x_refsource_confirm
http://www.adobe.com/support/security/bulletins/apsb11-21.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-1144.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14204

Scores

EPSS 0.0540
EPSS Percentile 91.9%

Details

CWE
CWE-264
Status published
Products (50)
adobe/adobe_air 1.0
adobe/adobe_air 1.1
adobe/adobe_air 1.5
adobe/adobe_air 1.5.2
adobe/adobe_air 1.5.3
adobe/adobe_air 2.0.2
adobe/adobe_air 2.0.3
adobe/adobe_air 2.0.4
adobe/adobe_air 2.6
adobe/adobe_air < 2.7
... and 40 more
Published Aug 10, 2011
Tracked Since Feb 18, 2026