Lucene search

K
cve[email protected]CVE-2008-3873
HistoryAug 29, 2008 - 5:41 p.m.

CVE-2008-3873

2008-08-2917:41:00
web.nvd.nist.gov
72
adobe flash player
actionscript
cve-2008-3873
clipboard vulnerability
remote attack

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.025

Percentile

90.1%

The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a URL that is difficult to delete and does not require user interaction to populate the clipboard, as exploited in the wild in August 2008.

Affected configurations

NVD
Node
adobeflash_player
VendorProductVersionCPE
adobeflash_playercpe:/a:adobe:flash_player::::

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.025

Percentile

90.1%