CVE-2008-4823
Summary
| CVE | CVE-2008-4823 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-10 14:12:55 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to loose interpretation of an ActionScript attribute. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Flash Player | 7.0.69.0 | All | All | All |
| Application | Adobe | Flash Player | 8.0.39.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.112.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.114.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.115.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.16 | All | All | All |
| Application | Adobe | Flash Player | 9.0.16 | All | windows | All |
| Application | Adobe | Flash Player | 9.0.18d60 | All | All | All |
| Application | Adobe | Flash Player | 9.0.20 | All | All | All |
| Application | Adobe | Flash Player | 9.0.20.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.28 | All | All | All |
| Application | Adobe | Flash Player | 9.0.28.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.28.0 | All | mac_os_x | All |
| Application | Adobe | Flash Player | 9.0.31 | All | All | All |
| Application | Adobe | Flash Player | 9.0.31.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.45.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.47.0 | All | All | All |
| Application | Adobe | Flash Player | 9.0.48.0 | All | All | All |
| Application | Adobe | Flash Player | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Adobe Flash Player Input Validation Hole Permits HTML Injection Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Adobe Flash Player Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| APPLE-SA-2008-12-15 Security Update 2008-008 / Mac OS X v10.5.6 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Gentoo Linux Documentation -- Adobe Flash Player: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| About the security content of Security Update 2008-008 / Mac OS X v10.5.6 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Technical Cyber Security Alert TA08-350A -- Apple Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| ASA-2008-440 (RHSA-2008-0980) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Adobe - Security Advisories: APSB08-20 - Flash Player update available to address security vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for flash-plugin - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ASA-2009-020 (SUN 248586) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Nortel: Technical Support: Nortel Response to Sun Alert 248586 - Multiple Security Vulnerabilities in the Flash Player Plugin for Solaris | af854a3a-2127-422b-91ae-364da2661108 | support.nortel.com | |
| Gentoo update for netscape-flash - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.