Lucene search

K
cveMitreCVE-2007-6149
HistoryFeb 13, 2008 - 9:00 p.m.

CVE-2007-6149

2008-02-1321:00:00
CWE-189
mitre
web.nvd.nist.gov
24
cve-2007-6149
adobe flash media server
connect enterprise server
integer overflow
remote code execution
rtmp
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.115

Percentile

95.3%

Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote attackers to execute arbitrary code via a Real Time Message Protocol (RTMP) message with a crafted integer field that is used for allocation.

Affected configurations

Nvd
Node
adobeconnect_enterprise_serverRange≀6sp2
OR
adobeflash_media_server_2Range≀2.0.4
VendorProductVersionCPE
adobeconnect_enterprise_server*cpe:2.3:a:adobe:connect_enterprise_server:*:sp2:*:*:*:*:*:*
adobeflash_media_server_2*cpe:2.3:a:adobe:flash_media_server_2:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.115

Percentile

95.3%