CVE-2007-0071

Description

Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
84.051

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe flash player 9.0.48.0 to latest versionWindows
Upgrade air 1.0 to latest versionWindows
Multiple vulnerabilities affected in Adobe Flash Player Plugin 9.0.48.0Windows
Multiple vulnerabilities affected in Adobe Flash Player PPAPI 9.0.48.0Windows
Vulnerability CVE-2007-0071,CVE-2007-6637,CVE-2008-1655 are affected in Adobe Flash Player 11 ActiveX 9.0.115.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234