Vulnerabilities > Adobe > Flex SDK > 1.5

DATE CVE VULNERABILITY TITLE RISK
2009-08-21 CVE-2009-1879 Cross-Site Scripting vulnerability in Adobe Flex SDK 1.5/3.3
Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to inject arbitrary web script or HTML via the query string.
network
high complexity
adobe CWE-79
2.6
2006-09-12 CVE-2006-3311 Remote Code Execution vulnerability in Adobe Flash Player
Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.
network
high complexity
adobe
5.1