CVE-2011-2458

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
11/11/2011
Last modified:
11/04/2025

Description

Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, when Internet Explorer is used, allows remote attackers to bypass the cross-domain policy via a crafted web site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* 10.0 (including) 10.3.183.11 (excluding)
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* 11.0 (including) 11.1.102.55 (excluding)
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:sun:solaris:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* 11.0 (including) 11.1.102.59 (excluding)
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:* 3.0 (including) 3.1.0.4880 (excluding)