← Back

CVE-2008-1834

nvd nist
Published: Apr 16, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

swfdec_load_object.c in Swfdec before 0.6.4 does not properly restrict local file access from untrusted sandboxes, which allows remote attackers to read arbitrary files via a crafted Flash file.

Affected (15)

Products: Swfdec: Swfdec
1 product
Swfdec
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Swfdec
Up to 0.6.2
Version 0.4.0
Version 0.4.1
Version 0.4.2
Version 0.4.3
Version 0.4.4
Version 0.4.5
Version 0.5.0
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.5.4
Version 0.5.5
Version 0.5.90
Version 0.6.0

Related CWEs

Timeline

No history available yet.