Lucene search

K
cveMitreCVE-2007-4324
HistoryAug 14, 2007 - 12:17 a.m.

CVE-2007-4324

2007-08-1400:17:00
CWE-264
mitre
web.nvd.nist.gov
67
cve-2007-4324
actionscript 3
as3
adobe flash player
security sandbox model
remote attack
port scan
timing discrepancies
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.162

Percentile

96.1%

ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.

Affected configurations

Nvd
Node
adobeflash_playerRangeโ‰ค9.0.114.0
VendorProductVersionCPE
adobeflash_playercpe:/a:adobe:flash_player::::

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.162

Percentile

96.1%