Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to loose interpretation of an ActionScript attribute.
http://www.vupen.com/english/advisories/2008/3444
http://www.us-cert.gov/cas/techalerts/TA08-350A.html
http://www.securitytracker.com/id?1021151
http://www.securityfocus.com/bid/32129
http://www.redhat.com/support/errata/RHSA-2008-0980.html
http://www.adobe.com/support/security/bulletins/apsb08-20.html
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=
http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
http://support.apple.com/kb/HT3338
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
http://security.gentoo.org/glsa/glsa-200903-23.xml
http://secunia.com/advisories/34226
http://secunia.com/advisories/33390
http://secunia.com/advisories/33179
http://secunia.com/advisories/32702
http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html