MEDIUM · 4.3

CVE-2009-0522

Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse point...

Vulnerability Description

Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related to a "Clickjacking attack."

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
AdobeAir1.5
AdobeFlash Player<= 10.0.12.36
AdobeFlash Player For Linux<= 10.0.15.3
AdobeFlex3.0
MicrosoftWindowsAll versions

References

FAQ

What is CVE-2009-0522?

CVE-2009-0522 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse point...

How severe is CVE-2009-0522?

CVE-2009-0522 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0522?

Check the references section above for vendor advisories and patch information. Affected products include: Adobe Air, Adobe Flash Player, Adobe Flash Player For Linux, Adobe Flex, Microsoft Windows.