CVE-2007-6019
published 2008-04-09CVE-2007-6019: Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified…
PriorityP263critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
59.77%
99.0th percentile
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | — | — |
| adobe | flash | — | — |
| adobe | flash | — | — |
| adobe | flash_player | <= 9.0.115.0 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts targeting the DeclareFunction2 ActionScript tag in SWF files; malicious SWF files will contain a modified/malformed DeclareFunction2 tag that prevents proper object instantiation. ↗
- →Flag delivery or execution of SWF files exploiting this vulnerability; the attack vector is a specially crafted .SWF file delivered to the Flash Player. ↗
- ·Vulnerable versions are Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier; Flash Player 9.0.124.0 is the patched version. Detections should target environments still running these older versions. ↗
- ·Adobe Flash Player 9.0.124.0 addresses this vulnerability; systems upgraded to this version or later are not affected. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9g7g-pmg2-qx9r: Adobe Flash Player 9
ghsa_unreviewed·2022-05-01
CVE-2007-6019 [HIGH] GHSA-9g7g-pmg2-qx9r: Adobe Flash Player 9
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
Red Hat
Flash Player input validation error
vendor_redhat·2008-04-08·CVSS 9.3
CVE-2007-6019 [CRITICAL] CWE-20 Flash Player input validation error
Flash Player input validation error
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
No detection rules found.
http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.htmlhttp://secunia.com/advisories/29763http://secunia.com/advisories/29865http://secunia.com/advisories/30430http://secunia.com/advisories/30507http://securityreason.com/securityalert/3805http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1http://www.adobe.com/support/security/bulletins/apsb08-11.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-21.xmlhttp://www.redhat.com/support/errata/RHSA-2008-0221.htmlhttp://www.securityfocus.com/archive/1/490623/100/0/threadedhttp://www.securityfocus.com/archive/1/490824/100/0/threadedhttp://www.securityfocus.com/bid/28694http://www.securitytracker.com/id?1019810http://www.us-cert.gov/cas/techalerts/TA08-100A.htmlhttp://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2008/1697http://www.vupen.com/english/advisories/2008/1724/referenceshttp://www.zerodayinitiative.com/advisories/ZDI-08-021https://exchange.xforce.ibmcloud.com/vulnerabilities/41717https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10160http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.htmlhttp://secunia.com/advisories/29763http://secunia.com/advisories/29865http://secunia.com/advisories/30430http://secunia.com/advisories/30507http://securityreason.com/securityalert/3805http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1http://www.adobe.com/support/security/bulletins/apsb08-11.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-21.xmlhttp://www.redhat.com/support/errata/RHSA-2008-0221.htmlhttp://www.securityfocus.com/archive/1/490623/100/0/threadedhttp://www.securityfocus.com/archive/1/490824/100/0/threadedhttp://www.securityfocus.com/bid/28694http://www.securitytracker.com/id?1019810http://www.us-cert.gov/cas/techalerts/TA08-100A.htmlhttp://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2008/1697http://www.vupen.com/english/advisories/2008/1724/referenceshttp://www.zerodayinitiative.com/advisories/ZDI-08-021https://exchange.xforce.ibmcloud.com/vulnerabilities/41717https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10160
2008-04-09
Published