CVE-2008-4823Cross-site Scripting in Adobe Flash Player

Severity
4.3MEDIUMNVD
EPSS
17.7%
top 4.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 10
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to loose interpretation of an ActionScript attribute.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDadobe/flash_player9.0.124.0+17

Patches

🔴Vulnerability Details

1
GHSA
GHSA-rhg8-59hr-g9r4: Cross-site scripting (XSS) vulnerability in Adobe Flash Player 92022-05-14

📋Vendor Advisories

1
Red Hat
Flash Player HTML injection flaw2008-11-05

💬Community

1
Bugzilla
CVE-2008-4823 Flash Player HTML injection flaw2008-11-05