CVE-2008-1655: XSS
Published Apr 9, 2008
·Updated
Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.
Affected Software
3 affected components
Adobe AIR=1.0
Adobe Flash Player<=9.0.115.0
Adobe Flex=3.0
Event History
Apr 9, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1655?
CVE-2008-1655 is classified as a medium severity vulnerability that can lead to DNS rebinding attacks.
2
How do I fix CVE-2008-1655?
To mitigate CVE-2008-1655, users should update to the latest version of Adobe Flash Player or Adobe AIR.
3
Which versions of Adobe Flash Player are affected by CVE-2008-1655?
CVE-2008-1655 affects Adobe Flash Player versions up to and including 9.0.115.0.
4
Can CVE-2008-1655 affect Adobe Flex?
Yes, CVE-2008-1655 can affect Adobe Flex 3.0 and earlier versions.
5
What types of attacks can CVE-2008-1655 enable?
CVE-2008-1655 enables remote attackers to conduct DNS rebinding attacks, facilitating unauthorized actions on behalf of the user.