Severity
6.8MEDIUMNVD
CISA9.8CISA7.8
EPSS
12.0%
top 6.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateOct 27

Description

Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

NVDadobe/flash_player5 versions+4
NVDopera/opera_browser44 versions+43

🔴Vulnerability Details

2
GHSA
GHSA-x42c-gqrm-5gfv: Adobe Macromedia Flash Player 7 and 9, when used with Opera before 92022-05-03
CVEList
CVE-2007-2022: Adobe Macromedia Flash Player 7 and 9, when used with Opera before 92007-04-13

💥Exploits & PoCs

1
Exploit-DB
News Rover 12.1 Rev 1 - Stack Overflow (2)2007-02-24

📋Vendor Advisories

5
Microsoft
Chromium: CVE-2022-2007 Use after free in WebGPU2022-06-14
Chrome
Stable Channel Update for Desktop: CVE-2022-20072022-06-09
CISA
Adobe Acrobat and Reader Buffer Overflow Vulnerability2022-06-08
CISA
Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability2022-04-15
Red Hat
kdebase3 flash-player interaction problem2007-05-25

🕵️Threat Intelligence

1
Trendmicro
Where is the Origin QAKBOT Uses Valid Code Signing2022-10-27

💬Community

1
Bugzilla
CVE-2007-2022 kdebase3 flash-player interaction problem2007-06-10
CVE-2007-2022 — Sensitive Information Exposure in Adobe | cvebase