Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4401
Description:ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file.
Test IDs: 1.3.6.1.4.1.25623.1.0.61802  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4401
http://security.gentoo.org/glsa/glsa-200903-23.xml
RedHat Security Advisories: RHSA-2008:0945
http://www.redhat.com/support/errata/RHSA-2008-0945.html
RedHat Security Advisories: RHSA-2008:0980
http://www.redhat.com/support/errata/RHSA-2008-0980.html
http://securitytracker.com/id?1021061
http://secunia.com/advisories/32270
http://secunia.com/advisories/32448
http://secunia.com/advisories/32702
http://secunia.com/advisories/32759
http://secunia.com/advisories/33390
http://secunia.com/advisories/34226
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
SuSE Security Announcement: SUSE-SR:2008:025 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
http://www.vupen.com/english/advisories/2008/2838
XForce ISS Database: adobe-flash-filereference-file-upload(45913)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45913




© 1998-2025 E-Soft Inc. All rights reserved.