CVE-2008-3873
Published · Updated
30Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 16%
from disclosure to weapon
Published on NVDAug 29
VulnCheckAug 29
exploitation probability
16%top 3% of all CVEs
observed exploitation
yesVulnCheck
The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a URL that is difficult to delete and does not require user interaction to populate the clipboard, as exploited in the wild in August 2008.
Affected products
n/a · n/aReferences
http://blogs.adobe.com/psirt/2008/08/clipboard_attack.htmlhttp://blogs.zdnet.com/security/?p=1733http://blogs.zdnet.com/security/?p=1759http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://secunia.com/advisories/32448http://secunia.com/advisories/32702http://secunia.com/advisories/32759http://secunia.com/advisories/33390http://secunia.com/advisories/34226http://security.gentoo.org/glsa/glsa-200903-23.xmlhttp://securitytracker.com/id?1020724https://exchange.xforce.ibmcloud.com/vulnerabilities/44584