CVE-2010-0190Cross-site Scripting in Adobe Acrobat

Severity
4.3MEDIUMNVD
EPSS
1.4%
top 19.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 2

Description

Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDadobe/acrobat_reader17 versions+16
NVDadobe/acrobat19 versions+18

Patches

🔴Vulnerability Details

1
GHSA
GHSA-457j-cjp6-q7h3: Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 92022-05-02

📋Vendor Advisories

1
Red Hat
Acroread: Multiple code execution flaws (APSB10-09)2010-04-13

💬Community

1
Bugzilla
Acroread: Multiple code execution flaws (APSB10-09)2010-04-12
CVE-2010-0190 — Cross-site Scripting in Adobe Acrobat | cvebase