CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
High
EPSS
Percentile
99.7%
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an “input validation error,” including a signed comparison of values that are assumed to be non-negative.
Vendor | Product | Version | CPE |
---|---|---|---|
adobe | flash_player | * | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
adobe | flash_player | 9.0.16 | cpe:2.3:a:adobe:flash_player:9.0.16:*:*:*:*:*:*:* |
adobe | flash_player | 9.0.18d60 | cpe:2.3:a:adobe:flash_player:9.0.18d60:*:*:*:*:*:*:* |
adobe | flash_player | 9.0.20 | cpe:2.3:a:adobe:flash_player:9.0.20:*:*:*:*:*:*:* |
adobe | flash_player | 9.0.20.0 | cpe:2.3:a:adobe:flash_player:9.0.20.0:*:*:*:*:*:*:* |
adobe | flash_player | 9.0.28 | cpe:2.3:a:adobe:flash_player:9.0.28:*:*:*:*:*:*:* |
adobe | flash_player | 9.0.28.0 | cpe:2.3:a:adobe:flash_player:9.0.28.0:*:*:*:*:*:*:* |
adobe | flash_player | 9.0.31 | cpe:2.3:a:adobe:flash_player:9.0.31:*:*:*:*:*:*:* |
adobe | flash_player | 9.0.31.0 | cpe:2.3:a:adobe:flash_player:9.0.31.0:*:*:*:*:*:*:* |
docs.info.apple.com/article.html?artnum=307041
lists.apple.com/archives/security-announce/2007/Nov/msg00002.html
osvdb.org/38054
secunia.com/advisories/26027
secunia.com/advisories/26057
secunia.com/advisories/26118
secunia.com/advisories/26357
secunia.com/advisories/27643
secunia.com/advisories/28068
sunsolve.sun.com/search/document.do?assetkey=1-26-103167-1
sunsolve.sun.com/search/document.do?assetkey=1-66-201506-1
www.adobe.com/support/security/bulletins/apsb07-12.html
www.gentoo.org/security/en/glsa/glsa-200708-01.xml
www.kb.cert.org/vuls/id/730785
www.mindedsecurity.com/labs/advisories/MSA01110707
www.novell.com/linux/security/advisories/2007_46_flashplayer.html
www.securityfocus.com/archive/1/473655/100/0/threaded
www.securityfocus.com/archive/1/474163/100/200/threaded
www.securityfocus.com/archive/1/474248/30/5760/threaded
www.securityfocus.com/bid/24856
www.securityfocus.com/bid/26444
www.securitytracker.com/id?1018359
www.us-cert.gov/cas/techalerts/TA07-192A.html
www.us-cert.gov/cas/techalerts/TA07-319A.html
www.vupen.com/english/advisories/2007/2497
www.vupen.com/english/advisories/2007/3868
www.vupen.com/english/advisories/2007/4190
exchange.xforce.ibmcloud.com/vulnerabilities/35337
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11493
rhn.redhat.com/errata/RHSA-2007-0696.html