CVE-2010-0190
Summary
| CVE | CVE-2010-0190 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-14 16:00:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Acrobat | 8.0 | All | All | All |
| Application | Adobe | Acrobat | 8.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat | 8.1.3 | All | All | All |
| Application | Adobe | Acrobat | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat | 8.1.5 | All | All | All |
| Application | Adobe | Acrobat | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat | 8.1.7 | All | All | All |
| Application | Adobe | Acrobat | 8.2 | All | All | All |
| Application | Adobe | Acrobat | 8.2.1 | All | All | All |
| Application | Adobe | Acrobat | 9.0 | All | All | All |
| Application | Adobe | Acrobat | 9.1 | All | All | All |
| Application | Adobe | Acrobat | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat | 9.1.3 | All | All | All |
| Application | Adobe | Acrobat | 9.2 | All | All | All |
| Application | Adobe | Acrobat | 9.3 | All | All | All |
| Application | Adobe | Acrobat | 9.3.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.7 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.2.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.3.1 | All | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| US-CERT Technical Cyber Security Alert TA10-103C -- Adobe Reader and Acrobat Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| RETIRED: Adobe Acrobat and Reader April 2010 Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Adobe - Security Bulletins: APSB10-09 - Security update available for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.