CVE-2009-3951 Information
Description
Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.
Reference
http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html http://osvdb.org/60891 http://secunia.com/advisories/37584 http://secunia.com/advisories/37902 http://secunia.com/advisories/38241 http://securitytracker.com/id?1023307 http://support.apple.com/kb/HT4004 http://www.adobe.com/support/security/bulletins/apsb09-19.html http://www.securityfocus.com/bid/37199 http://www.us-cert.gov/cas/techalerts/TA09-343A.html http://www.vupen.com/english/advisories/2009/3456 http://www.vupen.com/english/advisories/2010/0173 https://exchange.xforce.ibmcloud.com/vulnerabilities/54637 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A6663
Share on: