CVE-2008-4823

Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to loose interpretation of an ActionScript attribute.
References
Link Resource
http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html
http://secunia.com/advisories/32702
http://secunia.com/advisories/33179
http://secunia.com/advisories/33390
http://secunia.com/advisories/34226
http://security.gentoo.org/glsa/glsa-200903-23.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
http://support.apple.com/kb/HT3338
http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=
http://www.adobe.com/support/security/bulletins/apsb08-20.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0980.html
http://www.securityfocus.com/bid/32129 Patch
http://www.securitytracker.com/id?1021151
http://www.us-cert.gov/cas/techalerts/TA08-350A.html US Government Resource
http://www.vupen.com/english/advisories/2008/3444
http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html
http://secunia.com/advisories/32702
http://secunia.com/advisories/33179
http://secunia.com/advisories/33390
http://secunia.com/advisories/34226
http://security.gentoo.org/glsa/glsa-200903-23.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
http://support.apple.com/kb/HT3338
http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=
http://www.adobe.com/support/security/bulletins/apsb08-20.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0980.html
http://www.securityfocus.com/bid/32129 Patch
http://www.securitytracker.com/id?1021151
http://www.us-cert.gov/cas/techalerts/TA08-350A.html US Government Resource
http://www.vupen.com/english/advisories/2008/3444
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.69.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.39.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.16:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.16:*:windows:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.18d60:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.20:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.20.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.28.0:*:mac_os_x:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.31:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.31.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.45.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.47.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.48.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.112.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.114.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.115.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:52

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html - () http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html -
References () http://secunia.com/advisories/32702 - () http://secunia.com/advisories/32702 -
References () http://secunia.com/advisories/33179 - () http://secunia.com/advisories/33179 -
References () http://secunia.com/advisories/33390 - () http://secunia.com/advisories/33390 -
References () http://secunia.com/advisories/34226 - () http://secunia.com/advisories/34226 -
References () http://security.gentoo.org/glsa/glsa-200903-23.xml - () http://security.gentoo.org/glsa/glsa-200903-23.xml -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1 -
References () http://support.apple.com/kb/HT3338 - () http://support.apple.com/kb/HT3338 -
References () http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm - () http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm -
References () http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm - () http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm -
References () http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid= - () http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid= -
References () http://www.adobe.com/support/security/bulletins/apsb08-20.html - Patch, Vendor Advisory () http://www.adobe.com/support/security/bulletins/apsb08-20.html - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2008-0980.html - () http://www.redhat.com/support/errata/RHSA-2008-0980.html -
References () http://www.securityfocus.com/bid/32129 - Patch () http://www.securityfocus.com/bid/32129 - Patch
References () http://www.securitytracker.com/id?1021151 - () http://www.securitytracker.com/id?1021151 -
References () http://www.us-cert.gov/cas/techalerts/TA08-350A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA08-350A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2008/3444 - () http://www.vupen.com/english/advisories/2008/3444 -

Information

Published : 2008-11-10 14:12

Updated : 2024-11-21 00:52


NVD link : CVE-2008-4823

Mitre link : CVE-2008-4823

CVE.ORG link : CVE-2008-4823


JSON object : View

Products Affected

adobe

  • flash_player
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')