CVE-2008-4822
published 2008-11-10CVE-2008-4822: Adobe Flash Player 9.0.124.0 and earlier does not properly interpret policy files, which allows remote attackers to bypass a non-root domain policy.
PriorityP338medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.24%
91.6th percentile
Adobe Flash Player 9.0.124.0 and earlier does not properly interpret policy files, which allows remote attackers to bypass a non-root domain policy.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 9.0.124.0 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Flash Player policy file interpretation flaw
vendor_redhat·2008-11-05·CVSS 6.8
CVE-2008-4822 [MEDIUM] Flash Player policy file interpretation flaw
Flash Player policy file interpretation flaw
Adobe Flash Player 9.0.124.0 and earlier does not properly interpret policy files, which allows remote attackers to bypass a non-root domain policy.
GHSA
GHSA-j8g5-fv8j-f45c: Adobe Flash Player 9
ghsa_unreviewed·2022-05-14
CVE-2008-4822 [MEDIUM] GHSA-j8g5-fv8j-f45c: Adobe Flash Player 9
Adobe Flash Player 9.0.124.0 and earlier does not properly interpret policy files, which allows remote attackers to bypass a non-root domain policy.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.htmlhttp://secunia.com/advisories/32702http://secunia.com/advisories/33179http://secunia.com/advisories/33390http://secunia.com/advisories/34226http://security.gentoo.org/glsa/glsa-200903-23.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1http://support.apple.com/kb/HT3338http://support.avaya.com/elmodocs2/security/ASA-2008-440.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-020.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=http://www.adobe.com/support/security/bulletins/apsb08-20.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0980.htmlhttp://www.securityfocus.com/bid/32129http://www.securitytracker.com/id?1021150http://www.us-cert.gov/cas/techalerts/TA08-350A.htmlhttp://www.vupen.com/english/advisories/2008/3444https://exchange.xforce.ibmcloud.com/vulnerabilities/46535http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.htmlhttp://secunia.com/advisories/32702http://secunia.com/advisories/33179http://secunia.com/advisories/33390http://secunia.com/advisories/34226http://security.gentoo.org/glsa/glsa-200903-23.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1http://support.apple.com/kb/HT3338http://support.avaya.com/elmodocs2/security/ASA-2008-440.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-020.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=http://www.adobe.com/support/security/bulletins/apsb08-20.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0980.htmlhttp://www.securityfocus.com/bid/32129http://www.securitytracker.com/id?1021150http://www.us-cert.gov/cas/techalerts/TA08-350A.htmlhttp://www.vupen.com/english/advisories/2008/3444https://exchange.xforce.ibmcloud.com/vulnerabilities/46535
2008-11-10
Published