VulnerabilityModified
CVE-2008-4824
Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."
HIGH 9.3EPSS 13.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 13.25% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- adobe/flash player
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.htmlMailing List, Third Party Advisory
- http://osvdb.org/49958Broken Link
- http://secunia.com/advisories/32702Third Party Advisory
- http://secunia.com/advisories/32772Third Party Advisory
- http://secunia.com/advisories/33179Third Party Advisory
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1Broken Link
- http://support.apple.com/kb/HT3338Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=Broken Link
- http://www.adobe.com/support/security/bulletins/apsb08-22.htmlPatch, Vendor Advisory
- http://www.isecpartners.com/advisories/2008-01-flash.txtThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0980.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/498561/100/0/threadedThird Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-350A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/3189Third Party Advisory
- http://www.vupen.com/english/advisories/2008/3444Third Party Advisory
- http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.htmlMailing List, Third Party Advisory
- http://osvdb.org/49958Broken Link
- http://secunia.com/advisories/32702Third Party Advisory
- http://secunia.com/advisories/32772Third Party Advisory
- http://secunia.com/advisories/33179Third Party Advisory
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1Broken Link
- http://support.apple.com/kb/HT3338Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.