4.3

CVE-2009-1867

Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "clickjacking vulnerability."

Data is provided by the National Vulnerability Database (NVD)
AdobeAir Version <= 1.5.1
AdobeAir Version1.0
AdobeAir Version1.01
AdobeAir Version1.1
AdobeAir Version1.5
AdobeFlash Player Version <= 10.0.22.87
AdobeFlash Player Version7.0
AdobeFlash Player Version7.0.1
AdobeFlash Player Version7.0.25
AdobeFlash Player Version7.0.63
AdobeFlash Player Version7.0.63 Editionlinux
AdobeFlash Player Version7.0.69.0
AdobeFlash Player Version7.0.70.0
AdobeFlash Player Version7.1
AdobeFlash Player Version7.1.1
AdobeFlash Player Version7.2
AdobeFlash Player Version8.0
AdobeFlash Player Version8.0 Editionbasic
AdobeFlash Player Version8.0 Editionpro
AdobeFlash Player Version8.0.24.0
AdobeFlash Player Version8.0.34.0
AdobeFlash Player Version8.0.35.0
AdobeFlash Player Version8.0.39.0
AdobeFlash Player Version9.0.16
AdobeFlash Player Version9.0.20
AdobeFlash Player Version9.0.20.0
AdobeFlash Player Version9.0.28
AdobeFlash Player Version9.0.28.0
AdobeFlash Player Version9.0.31.0
AdobeFlash Player Version9.0.45.0
AdobeFlash Player Version9.0.47.0
AdobeFlash Player Version9.0.48.0
AdobeFlash Player Version9.0.112.0
AdobeFlash Player Version9.0.114.0
AdobeFlash Player Version9.0.115.0
AdobeFlash Player Version9.0.124.0
AdobeFlash Player Version10.0.0.584
AdobeFlash Player Version10.0.12.10
AdobeFlash Player Version10.0.12.36
AdobeFlex Version3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.99% 0.759
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.