CVE-2011-2444

EXPLOITED IN THE WILD

Adobe Flash Player < 10.3.183.10 - Cross-Site Scripting via Crafted URL

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2011-2444 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48308
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15272
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-1333.html
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2011/09/stable-channel-update_20.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14050
Patch, Vendor Advisory x_refsource_confirm
http://www.adobe.com/support/security/bulletins/apsb11-26.html

Scores

EPSS 0.0270
EPSS Percentile 84.2%

Details

VulnCheck KEV 2011-09-22
InTheWild.io 2018-10-30
CWE
CWE-79
Status published
Products (50)
adobe/flash_player 6.0.21.0
adobe/flash_player 6.0.79
adobe/flash_player 7.0
adobe/flash_player 7.0.1
adobe/flash_player 7.0.14.0
adobe/flash_player 7.0.19.0
adobe/flash_player 7.0.24.0
adobe/flash_player 7.0.25
adobe/flash_player 7.0.53.0
adobe/flash_player 7.0.60.0
... and 40 more
Published Sep 22, 2011
Tracked Since Feb 18, 2026