CVE-2007-6019
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 59.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 59.77% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- adobe/air · adobe/flash · adobe/flash player · adobe/flex
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html
- http://secunia.com/advisories/29763Vendor Advisory
- http://secunia.com/advisories/29865Vendor Advisory
- http://secunia.com/advisories/30430Vendor Advisory
- http://secunia.com/advisories/30507Vendor Advisory
- http://securityreason.com/securityalert/3805
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1
- http://www.adobe.com/support/security/bulletins/apsb08-11.htmlPatch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml
- http://www.redhat.com/support/errata/RHSA-2008-0221.html
- http://www.securityfocus.com/archive/1/490623/100/0/threaded
- http://www.securityfocus.com/archive/1/490824/100/0/threaded
- http://www.securityfocus.com/bid/28694Exploit, Patch
- http://www.securitytracker.com/id?1019810
- http://www.us-cert.gov/cas/techalerts/TA08-100A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/1697
- http://www.vupen.com/english/advisories/2008/1724/references
- http://www.zerodayinitiative.com/advisories/ZDI-08-021
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41717
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10160
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html
- http://secunia.com/advisories/29763Vendor Advisory
- http://secunia.com/advisories/29865Vendor Advisory
- http://secunia.com/advisories/30430Vendor Advisory
- http://secunia.com/advisories/30507Vendor Advisory
- http://securityreason.com/securityalert/3805
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.