9.3

CVE-2008-5499

Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player For Linux Version <= 9.0.151.0
   Linux ≫ Linux Kernel
Adobe ≫ Flash Player For Linux Version 9.0.31
   Linux ≫ Linux Kernel
Adobe ≫ Flash Player For Linux Version 9.0.48.0
   Linux ≫ Linux Kernel
Adobe ≫ Flash Player For Linux Version 9.0.115.0
   Linux ≫ Linux Kernel
Adobe ≫ Flash Player For Linux Version 9.0.124.0
   Linux ≫ Linux Kernel
Adobe ≫ Flash Player For Linux Version 10.0.12.36
   Linux ≫ Linux Kernel
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 79.43% 0.996
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://secunia.com/advisories/34226
http://security.gentoo.org/glsa/glsa-200903-23.xml
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00006.html
http://osvdb.org/50796
http://secunia.com/advisories/33221
http://secunia.com/advisories/33267
http://secunia.com/advisories/33294
Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb08-24.html
Patch
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-1047.html
http://www.securityfocus.com/bid/32896
http://www.securitytracker.com/id?1021458
http://www.vupen.com/english/advisories/2008/3449
https://exchange.xforce.ibmcloud.com/vulnerabilities/47445