VYPR
Unrated severityNVD Advisory· Published Jun 9, 2011· Updated Apr 29, 2026

CVE-2011-2107

CVE-2011-2107

Description

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player before 10.3.181.22 on desktop and 10.3.185.22 on Android is vulnerable to a universal XSS attack allowing arbitrary script injection.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in Adobe Flash Player versions prior to 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and versions prior to 10.3.185.22 on Android. The flaw is described as a "universal cross-site scripting vulnerability" and can be triggered via unspecified vectors, allowing remote attackers to inject arbitrary web script or HTML [1][2].

Exploitation

An attacker can exploit this vulnerability by crafting a malicious Flash file or by embedding specially constructed content on a web page. No authentication is required, and the attack can be launched remotely. The user only needs to visit a page containing the malicious Flash content, making it a highly accessible attack vector for widespread exploitation [1][2].

Impact

Successful exploitation leads to arbitrary script execution in the context of the victim's browser. This can result in disclosure of sensitive information, session hijacking, or other actions that the user's browser can perform. The universal nature of the XSS means it can bypass security controls designed to isolate web content, potentially affecting any site the user visits [1][2].

Mitigation

Adobe released Flash Player 10.3.181.22 for desktop platforms and 10.3.185.23 for Android to address this vulnerability. Red Hat also issued an advisory (RHSA-2011:0850) for affected packages. Users should update to the latest version immediately. No workaround is documented; disabling Flash Player is a possible but extreme measure [1][2].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

128
  • Adobe Inc./Acrobat20 versions
    cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*+ 19 more
    • cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*range: <=10.0.3
    • cpe:2.3:a:adobe:acrobat:10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:10.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:10.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.4:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat:9.4.4:*:*:*:*:*:*:*
  • cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*+ 19 more
    • cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*range: <=10.0.3
    • cpe:2.3:a:adobe:acrobat_reader:10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:10.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:10.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.4:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:acrobat_reader:9.4.4:*:*:*:*:*:*:*
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 86 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=10.3.181.16
    • cpe:2.3:a:adobe:flash_player:10.0.0.584:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.0.12.10:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.0.12.36:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.0.15.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.0.22.87:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.0.32.18:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.0.42.34:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.0.45.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.102.64:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.105.6:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.106.16:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.52.14.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.52.15:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.53.64:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.82.76:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.85.3:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.92.10:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.92.8:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.95.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.1.95.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.2.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.2.152.32:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.2.152.33:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.2.153.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.2.154.13:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.2.154.25:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.2.156.12:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.2.157.51:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.2.159.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:10.3.181.14:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:6.0.21.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:6.0.79:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.14.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.19.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.24.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.25:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.53.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.60.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.61.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.63:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.66.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.67.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.68.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.69.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.70.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.0.73.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:8.0.22.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:8.0.24.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:8.0.33.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:8.0.34.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:8.0.35.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:8.0.39.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:8.0.42.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.112.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.114.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.115.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.124.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.125.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.151.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.152.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.155.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.159.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.16:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.18d60:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.20:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.20.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.246.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.260.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.262.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.277.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.28:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.28.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.283.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.31:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.31.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.45.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.47.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.48.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.125.0:*:*:*:*:*:*:*
  • Range: <=10.3.181.22 (Windows/Mac/Linux/Solaris), <=10.3.185.22 (Android)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

16

News mentions

0

No linked articles in our index yet.