[Forgot Password]
Login  Register Subscribe

24128

 
 

131615

 
 

112965

 
 

909

 
 

87854

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2009-1870Date: (C)2009-07-31   (M)2018-09-01


Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to obtain sensitive information via vectors involving saving an SWF file to a hard drive, related to a "local sandbox vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.9
Exploit Score: 3.9
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1022629
SUNALERT-266108
BID-35890
BID-35908
SECUNIA-36193
SECUNIA-36374
SECUNIA-36701
OSVDB-56778
ADV-2009-2086
APPLE-SA-2009-09-10-1
APPLE-SA-2009-09-10-2
GLSA-200908-04
flash-air-sandbox-info-disclosure(52180)
http://support.apple.com/kb/HT3864
http://support.apple.com/kb/HT3865
http://www.adobe.com/support/security/bulletins/apsb09-10.html
http://www.adobe.com/support/security/bulletins/apsb09-13.html

CPE    31
cpe:/a:adobe:flash_player:9.0.114.0
cpe:/a:adobe:flash_player:9.0.112.0
cpe:/a:adobe:flash_player:9.0.124.0
cpe:/a:adobe:flash_player:9.0.45.0
...
CWE    1
CWE-200
OVAL    6
oval:org.secpod.oval:def:400059
oval:org.secpod.oval:def:17974
oval:org.secpod.oval:def:17973
oval:org.secpod.oval:def:17976
...

© SecPod Technologies