CVE-2008-4401
Summary
| CVE | CVE-2008-4401 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-17 19:31:15 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Flash Player | 7.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.1 | All | All | All |
| Application | Adobe | Flash Player | 7.0.25 | All | All | All |
| Application | Adobe | Flash Player | 7.0.63 | All | All | All |
| Application | Adobe | Flash Player | 7.0.69.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0.70.0 | All | All | All |
| Application | Adobe | Flash Player | 7.0_r67 | All | All | All |
| Application | Adobe | Flash Player | 7.1 | All | All | All |
| Application | Adobe | Flash Player | 7.1.1 | All | All | All |
| Application | Adobe | Flash Player | 7.2 | All | All | All |
| Application | Adobe | Flash Player | 8.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.24.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.34.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.35.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.39.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.112.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.114.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.115.0 | All | All | All |
| Application | Adobe | Flash Player | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat update for flash-plugin - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2008:025 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Gentoo Linux Documentation -- Adobe Flash Player: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Adobe - Developer Center : Understanding the security changes in Flash Player 10 | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | |
| ASA-2008-440 (RHSA-2008-0980) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Adobe - Security Advisories : APSB08-18: Flash Player update available to address security vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityTracker.com Archives - Adobe Flash FileReference API Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for flash-plugin - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ASA-2009-020 (SUN 248586) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Gentoo update for netscape-flash - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.