CVE-2008-1655

Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.
References
Link Resource
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html
http://secunia.com/advisories/29763
http://secunia.com/advisories/29865
http://secunia.com/advisories/30430
http://secunia.com/advisories/30507
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1
http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security.html#goal_dns
http://www.adobe.com/support/security/bulletins/apsb08-11.html
http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml
http://www.osvdb.org/44283
http://www.redhat.com/support/errata/RHSA-2008-0221.html
http://www.securityfocus.com/bid/28697
http://www.securitytracker.com/id?1019808
http://www.us-cert.gov/cas/techalerts/TA08-100A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA08-150A.html US Government Resource
http://www.vupen.com/english/advisories/2008/1697
http://www.vupen.com/english/advisories/2008/1724/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/41807
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10724
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html
http://secunia.com/advisories/29763
http://secunia.com/advisories/29865
http://secunia.com/advisories/30430
http://secunia.com/advisories/30507
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1
http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security.html#goal_dns
http://www.adobe.com/support/security/bulletins/apsb08-11.html
http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml
http://www.osvdb.org/44283
http://www.redhat.com/support/errata/RHSA-2008-0221.html
http://www.securityfocus.com/bid/28697
http://www.securitytracker.com/id?1019808
http://www.us-cert.gov/cas/techalerts/TA08-100A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA08-150A.html US Government Resource
http://www.vupen.com/english/advisories/2008/1697
http://www.vupen.com/english/advisories/2008/1724/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/41807
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10724
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:air:1.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flex:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:45

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2008//May/msg00001.html - () http://lists.apple.com/archives/security-announce/2008//May/msg00001.html -
References () http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html - () http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html -
References () http://secunia.com/advisories/29763 - () http://secunia.com/advisories/29763 -
References () http://secunia.com/advisories/29865 - () http://secunia.com/advisories/29865 -
References () http://secunia.com/advisories/30430 - () http://secunia.com/advisories/30430 -
References () http://secunia.com/advisories/30507 - () http://secunia.com/advisories/30507 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1 -
References () http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security.html#goal_dns - () http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security.html#goal_dns -
References () http://www.adobe.com/support/security/bulletins/apsb08-11.html - () http://www.adobe.com/support/security/bulletins/apsb08-11.html -
References () http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml - () http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml -
References () http://www.osvdb.org/44283 - () http://www.osvdb.org/44283 -
References () http://www.redhat.com/support/errata/RHSA-2008-0221.html - () http://www.redhat.com/support/errata/RHSA-2008-0221.html -
References () http://www.securityfocus.com/bid/28697 - () http://www.securityfocus.com/bid/28697 -
References () http://www.securitytracker.com/id?1019808 - () http://www.securitytracker.com/id?1019808 -
References () http://www.us-cert.gov/cas/techalerts/TA08-100A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA08-100A.html - US Government Resource
References () http://www.us-cert.gov/cas/techalerts/TA08-150A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA08-150A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2008/1697 - () http://www.vupen.com/english/advisories/2008/1697 -
References () http://www.vupen.com/english/advisories/2008/1724/references - () http://www.vupen.com/english/advisories/2008/1724/references -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/41807 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/41807 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10724 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10724 -

Information

Published : 2008-04-09 21:05

Updated : 2024-11-21 00:45


NVD link : CVE-2008-1655

Mitre link : CVE-2008-1655

CVE.ORG link : CVE-2008-1655


JSON object : View

Products Affected

adobe

  • air
  • flash_player
  • flex
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')