CVE-2007-6242Improper Input Validation in Adobe Flash Player

Severity
6.8MEDIUMNVD
NVD4.3
EPSS
45.8%
top 2.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20
Latest updateMay 14

Description

Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation errors."

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDadobe/flash_player9.0.16.09.0.48.0

🔴Vulnerability Details

2
GHSA
GHSA-m227-w3jm-cmgq: Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash2022-05-14
GHSA
GHSA-9www-c4ch-pp3w: Unspecified vulnerability in Adobe Flash Player 92022-05-01

📋Vendor Advisories

1
Red Hat
flash: abitrary code execution2007-12-17

💬Community

1
Bugzilla
CVE-2007-6242 flash: abitrary code execution2007-12-05