Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb08 11 | — | Upgrade to Adobe Flash Player version 9.0.124.0 for WindowsUpgrade to Adobe Flash Player version 9.0.124.0 for LinuxUpgrade to Adobe Flash Player version 9.0.124.0 for Mac OS X | Jul 11, 2013 | Dec 19, 2007 |
| Adobe Flash Apsb08 18 | — | Upgrade to Adobe Flash Player version 9.0.151.0 for Mac OS XUpgrade to Adobe Flash Player version 10.0.12.36 for WindowsUpgrade to Adobe Flash Player version 9.0.151.0 for LinuxUpgrade to Adobe Flash Player version 10.0.12.36 for Mac OS XUpgrade to Adobe Flash Player version 9.0.151.0 for WindowsUpgrade to Adobe Flash Player version 10.0.12.36 for Linux | Jul 11, 2013 | Dec 19, 2007 |
| Apple Osx Flashplayerplugin | — | Upgrade macOS to the latest versionApply OS X security update 2008-008 | Dec 16, 2011 | Dec 19, 2007 |
| Freebsd | — | Upgrade linux-flashplugin | Dec 10, 2025 | Oct 17, 2008 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Dec 19, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade flash-player | Feb 17, 2015 | Dec 19, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub