Vulnerabilities > Adobe > Flash Player > 3

DATE CVE VULNERABILITY TITLE RISK
2008-11-10 CVE-2008-4818 Cross-Site Scripting vulnerability in Adobe Flash Player
Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP response headers.
network
adobe CWE-79
4.3
2008-10-17 CVE-2008-4401 Permissions, Privileges, and Access Controls vulnerability in Adobe Flash Player
ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file.
network
low complexity
adobe CWE-264
critical
10.0
2008-10-09 CVE-2008-4503 Clickjacking vulnerability in RETIRED: Adobe Flash Player
The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."
network
adobe
6.8
2008-04-09 CVE-2008-1655 Cross-Site Scripting vulnerability in Adobe Air, Flash Player and Flex
Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.
network
adobe CWE-79
4.3
2008-04-09 CVE-2007-6019 Remote Code Execution vulnerability in Adobe Flash Player SWF File 'DeclareFunction2' ActionScript Tag
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
network
adobe
critical
9.3
2007-12-20 CVE-2007-6246 Permissions, Privileges, and Access Controls vulnerability in Adobe Flash Player
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges.
4.4
2007-12-20 CVE-2007-6243 Permissions, Privileges, and Access Controls vulnerability in Adobe Flash Player
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.
network
adobe CWE-264
critical
9.3
2007-10-18 CVE-2007-5476 Unspecified vulnerability in Adobe Flash Player On Opera Browser For Mac OSX
Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9.24 on Mac OS X, has unknown "Highly Severe" impact and unknown attack vectors.
network
low complexity
apple adobe opera
critical
10.0
2007-08-14 CVE-2007-4324 Permissions, Privileges, and Access Controls vulnerability in Adobe Flash Player
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not.
network
low complexity
adobe CWE-264
5.0
2007-07-11 CVE-2007-3457 Cross-Site Request Forgery (CSRF) vulnerability in Adobe Flash Player
Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.
network
adobe CWE-352
4.3