6.8

CVE-2008-4503

The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version <= 9.0.124.0
Adobe ≫ Flash Player Version 7.0
Adobe ≫ Flash Player Version 7.0.1
Adobe ≫ Flash Player Version 7.0.25
Adobe ≫ Flash Player Version 7.0.63
Adobe ≫ Flash Player Version 7.0.63 Edition linux
Adobe ≫ Flash Player Version 7.0.69.0
Adobe ≫ Flash Player Version 7.0.70.0
Adobe ≫ Flash Player Version 7.0_r67
Adobe ≫ Flash Player Version 7.0_r67 Edition solaris
Adobe ≫ Flash Player Version 7.1
Adobe ≫ Flash Player Version 7.1.1
Adobe ≫ Flash Player Version 7.2
Adobe ≫ Flash Player Version 8 Edition pro
Adobe ≫ Flash Player Version 8 Edition professional
Adobe ≫ Flash Player Version 8.0
Adobe ≫ Flash Player Version 8.0.24.0
Adobe ≫ Flash Player Version 8.0.34.0
Adobe ≫ Flash Player Version 8.0.35.0
Adobe ≫ Flash Player Version 8.0.39.0
Adobe ≫ Flash Player Version 9.0
Adobe ≫ Flash Player Version 9.0.114.0
Adobe ≫ Flash Player Version 9.0.115.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.19% 0.896
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
http://secunia.com/advisories/32448
http://secunia.com/advisories/32702
http://secunia.com/advisories/32759
http://secunia.com/advisories/33390
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
http://www.adobe.com/support/security/bulletins/apsb08-18.html
Patch
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0945.html
http://www.redhat.com/support/errata/RHSA-2008-0980.html
http://secunia.com/advisories/34226
http://security.gentoo.org/glsa/glsa-200903-23.xml
http://blog.guya.net/2008/10/07/malicious-camera-spying-using-clickjacking/
http://ha.ckers.org/blog/20081007/clickjacking-details/
http://secunia.com/advisories/32163
Vendor Advisory
http://www.adobe.com/support/security/advisories/apsa08-08.html
Vendor Advisory
http://www.securityfocus.com/bid/31625
http://www.securitytracker.com/id?1020996
http://www.vupen.com/english/advisories/2008/2764
https://exchange.xforce.ibmcloud.com/vulnerabilities/45721