Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-4401
HistoryOct 17, 2008 - 12:00 a.m.

CVE-2008-4401

2008-10-1700:00:00
ubuntu.com
ubuntu.com
14

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.033

Percentile

91.3%

ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require
user interaction in conjunction with (1) the FileReference.browse operation
in the FileReference upload API or (2) the FileReference.download operation
in the FileReference download API, which allows remote attackers to create
a browse dialog box, and possibly have unspecified other impact, via an SWF
file.

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchflashplugin-nonfree<Β 9.0.246.0ubuntu1UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.033

Percentile

91.3%