CVE-2008-4818

Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP response headers.
References
Link Resource
http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html
http://secunia.com/advisories/32702
http://secunia.com/advisories/33179
http://secunia.com/advisories/33390
http://secunia.com/advisories/34226
http://security.gentoo.org/glsa/glsa-200903-23.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
http://support.apple.com/kb/HT3338
http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=
http://www.adobe.com/support/security/bulletins/apsb08-20.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0980.html
http://www.securityfocus.com/bid/32129 Patch
http://www.securitytracker.com/id?1021146
http://www.us-cert.gov/cas/techalerts/TA08-350A.html US Government Resource
http://www.vupen.com/english/advisories/2008/3444
https://exchange.xforce.ibmcloud.com/vulnerabilities/46531
http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html
http://secunia.com/advisories/32702
http://secunia.com/advisories/33179
http://secunia.com/advisories/33390
http://secunia.com/advisories/34226
http://security.gentoo.org/glsa/glsa-200903-23.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
http://support.apple.com/kb/HT3338
http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=
http://www.adobe.com/support/security/bulletins/apsb08-20.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0980.html
http://www.securityfocus.com/bid/32129 Patch
http://www.securitytracker.com/id?1021146
http://www.us-cert.gov/cas/techalerts/TA08-350A.html US Government Resource
http://www.vupen.com/english/advisories/2008/3444
https://exchange.xforce.ibmcloud.com/vulnerabilities/46531
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.69.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.39.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.16:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.16:*:windows:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.18d60:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.20:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.20.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28.0:*:mac_os_x:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.31:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.31.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.45.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.47.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.48.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.112.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.114.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.115.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:52

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html - () http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html -
References () http://secunia.com/advisories/32702 - () http://secunia.com/advisories/32702 -
References () http://secunia.com/advisories/33179 - () http://secunia.com/advisories/33179 -
References () http://secunia.com/advisories/33390 - () http://secunia.com/advisories/33390 -
References () http://secunia.com/advisories/34226 - () http://secunia.com/advisories/34226 -
References () http://security.gentoo.org/glsa/glsa-200903-23.xml - () http://security.gentoo.org/glsa/glsa-200903-23.xml -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1 -
References () http://support.apple.com/kb/HT3338 - () http://support.apple.com/kb/HT3338 -
References () http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm - () http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm -
References () http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm - () http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm -
References () http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid= - () http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid= -
References () http://www.adobe.com/support/security/bulletins/apsb08-20.html - Vendor Advisory () http://www.adobe.com/support/security/bulletins/apsb08-20.html - Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2008-0980.html - () http://www.redhat.com/support/errata/RHSA-2008-0980.html -
References () http://www.securityfocus.com/bid/32129 - Patch () http://www.securityfocus.com/bid/32129 - Patch
References () http://www.securitytracker.com/id?1021146 - () http://www.securitytracker.com/id?1021146 -
References () http://www.us-cert.gov/cas/techalerts/TA08-350A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA08-350A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2008/3444 - () http://www.vupen.com/english/advisories/2008/3444 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/46531 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/46531 -

Information

Published : 2008-11-10 14:12

Updated : 2024-11-21 00:52


NVD link : CVE-2008-4818

Mitre link : CVE-2008-4818

CVE.ORG link : CVE-2008-4818


JSON object : View

Products Affected

adobe

  • flash_player
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')