Show filters
131 Total Results
Displaying 121-130 of 131
Sort by:
Attacker Value
Unknown
CVE-2008-4401
Disclosure Date: October 17, 2008 (last updated October 04, 2023)
ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file.
0
Attacker Value
Unknown
CVE-2008-4546
Disclosure Date: October 14, 2008 (last updated October 04, 2023)
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.
0
Attacker Value
Unknown
CVE-2008-4503
Disclosure Date: October 09, 2008 (last updated October 04, 2023)
The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."
0
Attacker Value
Unknown
CVE-2007-6019
Disclosure Date: April 09, 2008 (last updated October 04, 2023)
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
0
Attacker Value
Unknown
CVE-2007-6637
Disclosure Date: January 04, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.
0
Attacker Value
Unknown
CVE-2007-6244
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer.
0
Attacker Value
Unknown
CVE-2007-6245
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote attackers to modify HTTP headers for client requests and conduct HTTP Request Splitting attacks.
0
Attacker Value
Unknown
CVE-2007-5476
Disclosure Date: October 18, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9.24 on Mac OS X, has unknown "Highly Severe" impact and unknown attack vectors.
0
Attacker Value
Unknown
CVE-2007-3456
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.
0
Attacker Value
Unknown
CVE-2007-2022
Disclosure Date: April 13, 2007 (last updated October 04, 2023)
Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.
0