CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
AI Score
Confidence
Low
EPSS
Percentile
76.7%
Adobe Flash Player 9.0.124.0 and earlier, when a Mozilla browser is used, does not properly interpret jar: URLs, which allows attackers to obtain sensitive information via unknown vectors.
Vendor | Product | Version | CPE |
---|---|---|---|
adobe | flash_player | 9.0.16 | cpe:/a:adobe:flash_player:9.0.16::: |
adobe | flash_player | 9.0.28.0 | cpe:/a:adobe:flash_player:9.0.28.0::: |
adobe | flash_player | 9.0.115.0 | cpe:/a:adobe:flash_player:9.0.115.0::: |
adobe | flash_player | 9.0.31 | cpe:/a:adobe:flash_player:9.0.31::: |
adobe | flash_player | 9.0.48.0 | cpe:/a:adobe:flash_player:9.0.48.0::: |
adobe | flash_player | 9.0.18d60 | cpe:/a:adobe:flash_player:9.0.18d60::: |
adobe | flash_player | 9.0.28 | cpe:/a:adobe:flash_player:9.0.28::: |
adobe | flash_player | 8.0.39.0 | cpe:/a:adobe:flash_player:8.0.39.0::: |
adobe | flash_player | 9.0.114.0 | cpe:/a:adobe:flash_player:9.0.114.0::: |
adobe | flash_player | 9.0.20 | cpe:/a:adobe:flash_player:9.0.20::: |
lists.apple.com/archives/security-announce//2008//Dec/msg00000.html
secunia.com/advisories/32702
secunia.com/advisories/33179
secunia.com/advisories/33390
secunia.com/advisories/34226
security.gentoo.org/glsa/glsa-200903-23.xml
sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
support.apple.com/kb/HT3338
support.avaya.com/elmodocs2/security/ASA-2008-440.htm
support.avaya.com/elmodocs2/security/ASA-2009-020.htm
support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=
www.adobe.com/support/security/bulletins/apsb08-20.html
www.redhat.com/support/errata/RHSA-2008-0980.html
www.securityfocus.com/bid/32129
www.securitytracker.com/id?1021149
www.us-cert.gov/cas/techalerts/TA08-350A.html
www.vupen.com/english/advisories/2008/3444
exchange.xforce.ibmcloud.com/vulnerabilities/46534