4.3
CVSSv2

CVE-2007-6637

Published: 04/01/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote malicious users to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash player 8.0.34.0

adobe flash player 8.0.35.0

adobe flash player 9.0.115.0

adobe flash player 9.0.31.0

adobe flash player 9.0.45.0

adobe flash player 7.0.70.0

adobe flash player 8.0

adobe flash player 9.0.28.0

adobe flash player 9.0.31

adobe flash player 7.0.25

adobe flash player 9.0.16

adobe flash player 9.0.18d60

adobe flash player 9.0.47.0

adobe flash player 9.0.48.0

adobe flash player 7.0.63

adobe flash player 7.0.69.0

adobe flash player 9.0.20.0

adobe flash player 9.0.28

Vendor Advisories

Debian Bug report logs - #459071 CVE-2007-6637: Multiple cross-site scripting (XSS) vulnerabilities Package: flashplugin-nonfree; Maintainer for flashplugin-nonfree is Bart Martens <bartm@debianorg>; Source for flashplugin-nonfree is src:flashplugin-nonfree (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeri ...