VulnerabilityModified
CVE-2007-2022
Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.
MEDIUM 6.8EPSS 4.33%
Does this matter?
Lower severity and a low EPSS score (4.33%). Track it; it rarely justifies an emergency change on its own.
Description
Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 4.33% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- adobe/flash player · opera/opera browser
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc
- http://secunia.com/advisories/24877Vendor Advisory
- http://secunia.com/advisories/25027Vendor Advisory
- http://secunia.com/advisories/25432Vendor Advisory
- http://secunia.com/advisories/25662Vendor Advisory
- http://secunia.com/advisories/25669Vendor Advisory
- http://secunia.com/advisories/25894Vendor Advisory
- http://secunia.com/advisories/25933Vendor Advisory
- http://secunia.com/advisories/26027Vendor Advisory
- http://secunia.com/advisories/26118Vendor Advisory
- http://secunia.com/advisories/26357Vendor Advisory
- http://secunia.com/advisories/26860Vendor Advisory
- http://secunia.com/advisories/28068Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103167-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201506-1
- http://www.adobe.com/support/security/advisories/apsa07-03.html
- http://www.adobe.com/support/security/bulletins/apsb07-12.htmlVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200708-01.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:138
- http://www.novell.com/linux/security/advisories/2007_12_sr.html
- http://www.novell.com/linux/security/advisories/2007_28_opera.html
- http://www.novell.com/linux/security/advisories/2007_46_flashplayer.html
- http://www.opera.com/support/search/view/858/
- http://www.redhat.com/support/errata/RHSA-2007-0494.html
- http://www.securityfocus.com/bid/23437
- http://www.securitytracker.com/id?1017903
- http://www.us-cert.gov/cas/techalerts/TA07-192A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/1361Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2497Vendor Advisory
- http://www.vupen.com/english/advisories/2007/4190Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.