Adobe Flash Player SWF Version Null Pointer Dereference Denial of Service Vulnerability
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64 and Adobe AIR before 188.8.131.5210 allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time as demonstrated by two responses that provide SWF files with different SWF version numbers.
- Apple Mac OS X
- Adobe Flash Player
- Adobe AIR