CVE-2007-6149Adobe Connect Enterprise Server vulnerability

CWE-1894 documents4 sources
Severity
10.0CRITICALNVD
EPSS
33.7%
top 3.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateMay 1

Description

Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote attackers to execute arbitrary code via a Real Time Message Protocol (RTMP) message with a crafted integer field that is used for allocation.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jcph-f36w-q69j: Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 22022-05-01
CVEList
CVE-2007-6149: Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 22008-02-13

💥Exploits & PoCs

1
Exploit-DB
Joomla! Component mDigg 2.2.8 - 'category' SQL Injection2008-12-24
CVE-2007-6149 — Adobe vulnerability | cvebase