CVE-2008-4473Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe Flash Player

Severity
9.3CRITICALNVD
EPSS
27.5%
top 3.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 17
Latest updateMay 2

Description

Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 allow remote attackers to execute arbitrary code via an SWF file containing long control parameters.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDadobe/flash_playercs3, mx_2004+1

🔴Vulnerability Details

1
GHSA
GHSA-gfph-g5w3-9g35: Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 allow remote attackers to execute arbitrary code via2022-05-02