Vulnerabilities > Adobe > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-11-10 CVE-2008-4818 Cross-Site Scripting vulnerability in Adobe Flash Player
Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP response headers.
network
adobe CWE-79
4.3
2008-11-05 CVE-2008-4816 Unspecified vulnerability in Adobe Acrobat and Acrobat Reader
Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via unknown vectors.
network
microsoft adobe
4.3
2008-10-14 CVE-2008-4546 Resource Management Errors vulnerability in Adobe Flash Player
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.
network
adobe CWE-399
4.3
2008-10-09 CVE-2008-4503 Clickjacking vulnerability in RETIRED: Adobe Flash Player
The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."
network
adobe
6.8
2008-09-15 CVE-2008-4071 Improper Input Validation vulnerability in Adobe Acrobat 9
A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.
network
low complexity
adobe microsoft CWE-20
5.0
2008-08-29 CVE-2008-3873 Unspecified vulnerability in Adobe Flash Player
The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a URL that is difficult to delete and does not require user interaction to populate the clipboard, as exploited in the wild in August 2008.
network
adobe
4.3
2008-08-13 CVE-2008-3516 Cross-Site Scripting vulnerability in Adobe Presenter 6/7
Multiple cross-site scripting (XSS) vulnerabilities in files generated by Adobe Presenter 6 and 7 before 7.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) viewer.swf and (2) loadflash.js, a different vulnerability than CVE-2008-3515.
network
adobe CWE-79
4.3
2008-08-13 CVE-2008-3515 Cross-Site Scripting vulnerability in Adobe Presenter 6/7
Multiple cross-site scripting (XSS) vulnerabilities in files generated by Adobe Presenter 6 and 7 before 7.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) viewer.swf and (2) loadflash.js, a different vulnerability than CVE-2008-3516.
network
adobe CWE-79
4.3
2008-07-09 CVE-2008-2991 Cross-Site Scripting vulnerability in Adobe Robohelp Server 6/7
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log.
network
adobe CWE-79
4.3
2008-06-18 CVE-2008-2640 Cross-Site Scripting vulnerability in Adobe Flex and Flex Builder
Multiple cross-site scripting (XSS) vulnerabilities in the Flex 3 History Management feature in Adobe Flex 3.0.1 SDK and Flex Builder 3, and generated applications, allow remote attackers to inject arbitrary web script or HTML via the anchor identifier to (1) client-side-detection-with-history/history/historyFrame.html, (2) express-installation-with-history/history/historyFrame.html, or (3) no-player-detection-with-history/history/historyFrame.html in templates/html-templates/.
network
adobe CWE-79
4.3