cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2011-2461,https://securityvulnerability.io/vulnerability/CVE-2011-2461,,Cross-site scripting (XSS) vulnerability in the Adobe Flex SDK 3.x and 4.x before 4.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the loading of modules from different domains.,Adobe,Flex Sdk,,,0.02676999941468239,false,,false,false,true,2015-02-08T05:49:07.000Z,true,false,false,,2011-12-01T11:00:00.000Z,0 CVE-2009-3960,https://securityvulnerability.io/vulnerability/CVE-2009-3960,,"Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.",Adobe,"Lifecycle,Coldfusion,Blazeds,Lifecycle Data Services,Flex Data Services",6.5,MEDIUM,0.9382100105285645,true,2022-03-07T00:00:00.000Z,false,true,true,2022-03-07T00:00:00.000Z,true,false,false,,2010-02-15T18:00:00.000Z,0 CVE-2009-1879,https://securityvulnerability.io/vulnerability/CVE-2009-1879,,"Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to inject arbitrary web script or HTML via the query string.",Adobe,Flex Sdk,,,0.010569999925792217,false,,false,false,false,,,false,false,,2009-08-21T17:00:00.000Z,0 CVE-2009-1866,https://securityvulnerability.io/vulnerability/CVE-2009-1866,,"Stack-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.",Adobe,"Air,Flash Player,Flex",,,0.006610000040382147,false,,false,false,false,,,false,false,,2009-07-31T19:00:00.000Z,0 CVE-2009-1863,https://securityvulnerability.io/vulnerability/CVE-2009-1863,,"Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to a ""privilege escalation vulnerability.""",Adobe,"Air,Flash Player,Flex",,,0.008469999767839909,false,,false,false,false,,,false,false,,2009-07-31T19:00:00.000Z,0 CVE-2009-1867,https://securityvulnerability.io/vulnerability/CVE-2009-1867,,"Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a ""clickjacking vulnerability.""",Adobe,"Air,Flash Player,Flex",,,0.006709999870508909,false,,false,false,false,,,false,false,,2009-07-31T19:00:00.000Z,0 CVE-2009-1864,https://securityvulnerability.io/vulnerability/CVE-2009-1864,,"Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.",Adobe,"Air,Flash Player,Flex",,,0.006610000040382147,false,,false,false,false,,,false,false,,2009-07-31T19:00:00.000Z,0 CVE-2009-1865,https://securityvulnerability.io/vulnerability/CVE-2009-1865,,"Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, related to a ""null pointer vulnerability.""",Adobe,"Air,Flash Player,Flex",,,0.007619999814778566,false,,false,false,false,,,false,false,,2009-07-31T19:00:00.000Z,0 CVE-2009-1868,https://securityvulnerability.io/vulnerability/CVE-2009-1868,,"Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing.",Adobe,"Air,Flash Player,Flex",,,0.006519999820739031,false,,false,false,false,,,false,false,,2009-07-31T19:00:00.000Z,0 CVE-2009-1869,https://securityvulnerability.io/vulnerability/CVE-2009-1869,,"Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2 file with a large intrf_count value that triggers a dereference of an out-of-bounds pointer.",Adobe,"Air,Flash Player,Flex",,,0.17177000641822815,false,,false,false,false,,,false,false,,2009-07-31T19:00:00.000Z,0 CVE-2009-1870,https://securityvulnerability.io/vulnerability/CVE-2009-1870,,"Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to obtain sensitive information via vectors involving saving an SWF file to a hard drive, related to a ""local sandbox vulnerability.""",Adobe,"Air,Flash Player,Flex",,,0.0008800000068731606,false,,false,false,false,,,false,false,,2009-07-31T19:00:00.000Z,0 CVE-2009-0520,https://securityvulnerability.io/vulnerability/CVE-2009-0520,,"Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a ""buffer overflow issue.""",Adobe,"Flash Player,Flash Player For Linux,Air,Flex",,,0.6622400283813477,false,,false,false,false,,,false,false,,2009-02-26T16:00:00.000Z,0 CVE-2009-0114,https://securityvulnerability.io/vulnerability/CVE-2009-0114,,"Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to ""a potential Clickjacking issue variant.""",Adobe,"Air,Flash Player,Flash Player For Linux,Flex",,,0.016580000519752502,false,,false,false,false,,,false,false,,2009-02-26T16:00:00.000Z,0 CVE-2009-0522,https://securityvulnerability.io/vulnerability/CVE-2009-0522,,"Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the ""mouse pointer display,"" related to a ""Clickjacking attack.""",Adobe,"Air,Flash Player,Flash Player For Linux,Flex",,,0.00788000039756298,false,,false,false,false,,,false,false,,2009-02-26T16:00:00.000Z,0 CVE-2009-0519,https://securityvulnerability.io/vulnerability/CVE-2009-0519,,Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a crafted Shockwave Flash (aka .swf) file.,Adobe,"Flash Player,Flash Player For Linux,Air,Flex",,,0.5259799957275391,false,,false,false,false,,,false,false,,2009-02-26T16:00:00.000Z,0 CVE-2008-2640,https://securityvulnerability.io/vulnerability/CVE-2008-2640,,"Multiple cross-site scripting (XSS) vulnerabilities in the Flex 3 History Management feature in Adobe Flex 3.0.1 SDK and Flex Builder 3, and generated applications, allow remote attackers to inject arbitrary web script or HTML via the anchor identifier to (1) client-side-detection-with-history/history/historyFrame.html, (2) express-installation-with-history/history/historyFrame.html, or (3) no-player-detection-with-history/history/historyFrame.html in templates/html-templates/. NOTE: Firefox 2.0 and possibly other browsers prevent exploitation.",Adobe,"Flex Builder,Flex",,,0.008229999803006649,false,,false,false,false,,,false,false,,2008-06-18T19:29:00.000Z,0 CVE-2007-6019,https://securityvulnerability.io/vulnerability/CVE-2007-6019,,"Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.",Adobe,"Flash Player,Air,Flash,Flex",,,0.44216999411582947,false,,false,false,false,,,false,false,,2008-04-09T21:00:00.000Z,0 CVE-2008-1655,https://securityvulnerability.io/vulnerability/CVE-2008-1655,,"Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.",Adobe,"Flash Player,Air,Flex",,,0.044130001217126846,false,,false,false,false,,,false,false,,2008-04-09T21:00:00.000Z,0 CVE-2006-3311,https://securityvulnerability.io/vulnerability/CVE-2006-3311,,"Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.",Adobe,"Flash Player,Flex Sdk",,,0.6880000233650208,false,,false,false,false,,,false,false,,2006-09-12T23:07:00.000Z,0