CVE-2008-3872
published 2008-10-06CVE-2008-3872: Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.84%
91.1th percentile
Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF file with unspecified "Filter evasion" manipulations.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | 8.0 – 8.0.39.0 | — |
| adobe | flash_player | 9.0 – 9.0.115.0 | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gm92-x63w-j26f: Adobe Flash Player 8
ghsa_unreviewed·2022-05-02
CVE-2008-3872 [HIGH] GHSA-gm92-x63w-j26f: Adobe Flash Player 8
Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF file with unspecified "Filter evasion" manipulations.
Red Hat
security flaw
vendor_redhat·2008-04-08·CVSS 9.3
CVE-2008-3872 [CRITICAL] security flaw
security flaw
Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF file with unspecified "Filter evasion" manipulations.
No detection rules found.
No public exploits indexed.
http://taviso.decsystem.org/research.htmlhttp://www.adobe.com/support/security/bulletins/apsb08-11.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/45713http://taviso.decsystem.org/research.htmlhttp://www.adobe.com/support/security/bulletins/apsb08-11.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/45713
2008-10-06
Published