CVE-2011-2444
EXPLOITED IN THE WILDAdobe Flash Player < 10.3.183.10 - Cross-Site Scripting via Crafted URL
Title source: llmExploitation Summary
CVE-2011-2444 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
Description
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.
References (7)
Core 7
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48308
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15272
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00025.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-1333.html
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2011/09/stable-channel-update_20.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14050
Patch, Vendor Advisory x_refsource_confirm
http://www.adobe.com/support/security/bulletins/apsb11-26.html
Scores
EPSS
0.0270
EPSS Percentile
84.2%
Details
VulnCheck KEV
2011-09-22
InTheWild.io
2018-10-30
CWE
CWE-79
Status
published
Products (50)
adobe/flash_player
6.0.21.0
adobe/flash_player
6.0.79
adobe/flash_player
7.0
adobe/flash_player
7.0.1
adobe/flash_player
7.0.14.0
adobe/flash_player
7.0.19.0
adobe/flash_player
7.0.24.0
adobe/flash_player
7.0.25
adobe/flash_player
7.0.53.0
adobe/flash_player
7.0.60.0
... and 40 more
Published
Sep 22, 2011
Tracked Since
Feb 18, 2026