MEDIUM · 5.8

CVE-2009-0114

Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visit...

Vulnerability Description

Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant."

CVSS Score

5.8

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AdobeAir1.5
AdobeFlash Player<= 10.0.12.36
AdobeFlash Player For Linux<= 10.0.15.3
AdobeFlex3.0
MicrosoftWindowsAll versions

References

FAQ

What is CVE-2009-0114?

CVE-2009-0114 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visit...

How severe is CVE-2009-0114?

CVE-2009-0114 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0114?

Check the references section above for vendor advisories and patch information. Affected products include: Adobe Air, Adobe Flash Player, Adobe Flash Player For Linux, Adobe Flex, Microsoft Windows.