← Vulnerability feed

Vulnerability record · CVE-2008-5499 · published 18 December 2008

CVE-2008-5499: Adobe Flash Player for Linux code injection via crafted SWF

Adobe · Flash Player For Linux

Adobe Flash Player for Linux 10.0.12.36 and 9.0.151.0 and earlier contain an unspecified code injection flaw (CWE-94) that lets a remote attacker execute arbitrary code through a crafted SWF file. The record does not describe the underlying mechanism, only that the vulnerability is unspecified, so the exact trigger is unknown. It matters because Flash content was widely embedded in web pages, giving the flaw a broad reach against Linux users running the affected versions.

9.3 CVSS 2.0 High EPSS 79% · top 0.4% CWE-94 · Code injection
9.3CVSS 2.0 base score
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote code execution with complete impact and a very high EPSS score, though exploitation is not confirmed in KEV and the flaw is unspecified.

What it is

Adobe Flash Player for Linux 10.0.12.36 and 9.0.151.0 and earlier contain an unspecified code injection flaw (CWE-94) that lets a remote attacker execute arbitrary code through a crafted SWF file. The record does not describe the underlying mechanism, only that the vulnerability is unspecified, so the exact trigger is unknown. It matters because Flash content was widely embedded in web pages, giving the flaw a broad reach against Linux users running the affected versions.

Impact

An attacker who gets a victim to load a malicious SWF gains arbitrary code execution in the context of the Flash Player process, which can lead to full compromise of the user's account and data. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.

Attack surface

Reached over the network by delivering a crafted SWF file, typically via a web page or embedded content. The vector AV:N/AC:M/Au:N indicates no authentication is required, but some user action such as visiting a page or opening the file is needed.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded. EPSS is very high (0.79426, 99.58th percentile), but the references carry no exploit tags, so active exploitation is not confirmed by this record.

What to do

  • Upgrade or remove the affected Flash Player for Linux versions; apply the Adobe APSB08-24 update or the distribution errata (Red Hat RHSA-2008-1047, Gentoo GLSA-200903-23, openSUSE advisory).
  • If Flash cannot be updated, disable or uninstall the plugin and block SWF content at the browser and proxy level.
  • Restrict browsing to trusted sites and enforce content filtering for Flash objects on Linux endpoints.
  • Track vendor advisories for the Linux distributions in use and confirm the patched package version is installed.

Detection

  • Monitor for Flash Player processes spawning unexpected child processes or making outbound network connections.
  • Alert on SWF files downloaded from untrusted or newly seen domains reaching Linux hosts.
  • Review endpoint logs for crashes or abnormal behavior in the Flash Player plugin around web browsing sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5499 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-0959Adobe flash player use after free vulnerabilityUse after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, …EPSS 5.2%9.3CVE-2010-2213Adobe air code injection vulnerabilityAdobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denia…EPSS 4.6%9.3CVE-2010-2214Adobe air code injection vulnerabilityAdobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denia…EPSS 4.6%9.3CVE-2010-2216Adobe air code injection vulnerabilityAdobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denia…EPSS 4.6%9.3CVE-2010-0209Adobe air code injection vulnerabilityAdobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denia…EPSS 4.6%9.3CVE-2009-0519Adobe air improper input validation vulnerabilityUnspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service …EPSS 15%9.3CVE-2009-0520Adobe air memory buffer overflow vulnerabilityAdobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash fi…EPSS 28%8.8CVE-2016-7865Adobe flash player vulnerabilityAdobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitatio…EPSS 7.2%

Source: NIST National Vulnerability Database (record CVE-2008-5499), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.