CVE-2008-4821Sensitive Information Exposure in Adobe Flash Player

Severity
4.3MEDIUMNVD
EPSS
5.7%
top 9.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 10
Latest updateMay 14

Description

Adobe Flash Player 9.0.124.0 and earlier, when a Mozilla browser is used, does not properly interpret jar: URLs, which allows attackers to obtain sensitive information via unknown vectors.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDadobe/flash_player9.0.124.0+17

Patches

🔴Vulnerability Details

1
GHSA
GHSA-r68f-43vp-85x9: Adobe Flash Player 92022-05-14

📋Vendor Advisories

1
Red Hat
jar: protocol handler2008-11-05

💬Community

1
Bugzilla
CVE-2008-4821 Flash Player jar: protocol handler2008-11-05