VYPR
Unrated severityNVD Advisory· Published Oct 14, 2008· Updated Apr 23, 2026

CVE-2008-4546

CVE-2008-4546

Description

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player and AIR crash via NULL pointer dereference when a server returns different SWF versions on retry.

Vulnerability

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, are vulnerable to a NULL pointer dereference when a remote web server returns a different HTTP response upon a subsequent request, such as providing two SWF files with different version numbers [4]. This condition triggers a denial of service via browser crash.

Exploitation

An attacker-controlled web server sends an initial response with a SWF file of a certain version, and then a second response with a different SWF version. When the Flash Player processes the differing responses, a NULL pointer dereference occurs, crashing the browser [4]. No authentication or user interaction beyond loading the SWF is required.

Impact

Successful exploitation results in a denial of service, causing the browser to crash. This is a CIA impact limited to availability, with no code execution or data compromise described [4].

Mitigation

Update to Adobe Flash Player 9.0.277.0 or 10.1.53.64, or Adobe AIR 2.0.2.12610 as recommended in Adobe Security Bulletin APSB10-14 [4]. No workarounds are available; disabling Flash is an alternative if updating is not possible.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

6
  • cpe:2.3:a:adobe:flash_player:10.0.12.10:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:adobe:flash_player:10.0.12.10:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.112.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.115.0:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:9.0.45.0:*:*:*:*:*:*:*
  • Adobe Inc./Airllm-fuzzy
    Range: <2.0.2.12610
  • Range: <9.0.277.0 (9.x) and <10.1.53.64 (10.x)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

32

News mentions

0

No linked articles in our index yet.