CVE-2010-0186
Summary
| CVE | CVE-2010-0186 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-15 18:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Acrobat | 8.0 | All | All | All |
| Application | Adobe | Acrobat | 8.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat | 8.1.3 | All | All | All |
| Application | Adobe | Acrobat | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat | 8.1.5 | All | All | All |
| Application | Adobe | Acrobat | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat | 8.1.7 | All | All | All |
| Application | Adobe | Acrobat | 9.0 | All | All | All |
| Application | Adobe | Acrobat | 9.1 | All | All | All |
| Application | Adobe | Acrobat | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat | 9.1.3 | All | All | All |
| Application | Adobe | Acrobat | 9.2 | All | All | All |
| Application | Adobe | Acrobat | All | All | All | All |
| Application | Adobe | Acrobat Reader | 8.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.7 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.2 | All | All | All |
| Application | Adobe | Acrobat Reader | All | All | All | All |
| Application | Adobe | Adobe Air | 1.0 | All | All | All |
| Application | Adobe | Adobe Air | 1.1 | All | All | All |
| Application | Adobe | Adobe Air | 1.5.1 | All | All | All |
| Application | Adobe | Adobe Air | 1.5.2 | All | All | All |
| Application | Adobe | Adobe Air | 1.5.3 | All | All | All |
| Application | Adobe | Adobe Air | All | All | All | All |
| Application | Adobe | Flash Player | 10.0.12.10 | All | All | All |
| Application | Adobe | Flash Player | 10.0.12.36 | All | All | All |
| Application | Adobe | Flash Player | 10.0.15.3 | All | All | All |
| Application | Adobe | Flash Player | 10.0.22.87 | All | All | All |
| Application | Adobe | Flash Player | 10.0.32.18 | All | All | All |
| Application | Adobe | Flash Player | 6.0.21.0 | All | All | All |
| Application | Adobe | Flash Player | 6.0.79 | All | All | All |
| Application | Adobe | Flash Player | 7.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.1 | All | All | All |
| Application | Adobe | Flash Player | 7.0.25 | All | All | All |
| Application | Adobe | Flash Player | 7.0.63 | All | All | All |
| Application | Adobe | Flash Player | 7.0.69.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.70.0 | All | All | All |
| Application | Adobe | Flash Player | 7.1 | All | All | All |
| Application | Adobe | Flash Player | 7.1.1 | All | All | All |
| Application | Adobe | Flash Player | 7.2 | All | All | All |
| Application | Adobe | Flash Player | 8.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.22.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.24.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.33.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.34.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.35.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.39.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.42.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.112.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.114.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.115.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.124.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.125.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.151.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.152.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.159.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.16 | All | All | All |
| Application | Adobe | Flash Player | 9.0.18d60 | All | All | All |
| Application | Adobe | Flash Player | 9.0.20 | All | All | All |
| Application | Adobe | Flash Player | 9.0.20.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.246.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.260.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.28.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.31 | All | All | All |
| Application | Adobe | Flash Player | 9.0.31.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.45.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.47.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.48.0 | All | All | All |
| Application | Adobe | Flash Player | 9.125.0 | All | All | All |
| Application | Adobe | Flash Player | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Adobe Flash Player Domain Sandbox Bypass Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat update for acroread - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:006 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Bug 563819 – CVE-2010-0186 flash-plugin: unauthorized cross-domain requests (APSB10-06) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Adobe - Security Bulletins: APSB10-07 Security updates available for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| Gentoo Linux Documentation -- Adobe Flash Player: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityTracker.com Archives - Adobe Flash Player Flaw Lets Remote Users Issue Cross-Domain Requests | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo update for adobe-flash - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Multiple Adobe Products Unspecified Cross Domain Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| SUSE Update for Multiple Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.osvdb.org/62300 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| About the security content of Security Update 2010-004 / Mac OS X v10.6.4 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Adobe - Security Bulletins: APSB10-06 Security update available for Adobe Flash Player | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| APPLE-SA-2010-06-15-1 Security Update 2010-004 / Mac OS X v10.6.4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.