CVE-2011-2444
Summary
| CVE | CVE-2011-2444 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-09-22 03:38:38 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Flash Player | 10.0.0.584 | All | All | All |
| Application | Adobe | Flash Player | 10.0.12.10 | All | All | All |
| Application | Adobe | Flash Player | 10.0.12.36 | All | All | All |
| Application | Adobe | Flash Player | 10.0.15.3 | All | All | All |
| Application | Adobe | Flash Player | 10.0.22.87 | All | All | All |
| Application | Adobe | Flash Player | 10.0.32.18 | All | All | All |
| Application | Adobe | Flash Player | 10.0.42.34 | All | All | All |
| Application | Adobe | Flash Player | 10.0.45.2 | All | All | All |
| Application | Adobe | Flash Player | 10.1.102.64 | All | All | All |
| Application | Adobe | Flash Player | 10.1.52.14.1 | All | All | All |
| Application | Adobe | Flash Player | 10.1.52.15 | All | All | All |
| Application | Adobe | Flash Player | 10.1.53.64 | All | All | All |
| Application | Adobe | Flash Player | 10.1.82.76 | All | All | All |
| Application | Adobe | Flash Player | 10.1.85.3 | All | All | All |
| Application | Adobe | Flash Player | 10.1.92.10 | All | All | All |
| Application | Adobe | Flash Player | 10.1.92.8 | All | All | All |
| Application | Adobe | Flash Player | 10.1.95.1 | All | All | All |
| Application | Adobe | Flash Player | 10.1.95.2 | All | All | All |
| Application | Adobe | Flash Player | 10.2.152 | All | All | All |
| Application | Adobe | Flash Player | 10.2.152.32 | All | All | All |
| Application | Adobe | Flash Player | 10.2.152.33 | All | All | All |
| Application | Adobe | Flash Player | 10.2.154.13 | All | All | All |
| Application | Adobe | Flash Player | 10.2.154.25 | All | All | All |
| Application | Adobe | Flash Player | 10.2.159.1 | All | All | All |
| Application | Adobe | Flash Player | 10.3.181.14 | All | All | All |
| Application | Adobe | Flash Player | 10.3.181.16 | All | All | All |
| Application | Adobe | Flash Player | 10.3.181.23 | All | All | All |
| Application | Adobe | Flash Player | 10.3.181.34 | All | All | All |
| Application | Adobe | Flash Player | 10.3.181.36 | All | All | All |
| Application | Adobe | Flash Player | 10.3.183.5 | All | All | All |
| Application | Adobe | Flash Player | 6.0.21.0 | All | All | All |
| Application | Adobe | Flash Player | 6.0.79 | All | All | All |
| Application | Adobe | Flash Player | 7.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.1 | All | All | All |
| Application | Adobe | Flash Player | 7.0.14.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.19.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.24.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.25 | All | All | All |
| Application | Adobe | Flash Player | 7.0.53.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.60.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.61.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.63 | All | All | All |
| Application | Adobe | Flash Player | 7.0.66.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.67.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.68.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.69.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.70.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.73.0 | All | All | All |
| Application | Adobe | Flash Player | 7.1 | All | All | All |
| Application | Adobe | Flash Player | 7.1.1 | All | All | All |
| Application | Adobe | Flash Player | 7.2 | All | All | All |
| Application | Adobe | Flash Player | 8.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.22.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.24.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.33.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.34.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.35.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.39.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.42.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.112.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.114.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.115.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.124.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.125.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.151.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.152.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.155.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.159.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.16 | All | All | All |
| Application | Adobe | Flash Player | 9.0.18d60 | All | All | All |
| Application | Adobe | Flash Player | 9.0.20 | All | All | All |
| Application | Adobe | Flash Player | 9.0.20.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.246.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.260.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.262.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.277.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.28 | All | All | All |
| Application | Adobe | Flash Player | 9.0.28.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.283.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.31 | All | All | All |
| Application | Adobe | Flash Player | 9.0.31.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.45.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.47.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.48.0 | All | All | All |
| Application | Adobe | Flash Player | 9.125.0 | All | All | All |
| Application | Adobe | Flash Player | All | All | All | All |
| Application | Adobe | Flash Player | All | All | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
| Operating System | Sun | Sunos | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Adobe - Security Bulletins: APSB11-26 - Security updates available for Adobe Flash Player | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [security-announce] SUSE-SU-2011:1063-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.