CVE-2007-5275

Description

The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browsers DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
37.246

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Adobe Shockwave Player 9Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player for Mac 9Mac
Vulnerabilities CVE-2007-5275 are affected in Wave for Mac 9Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-309312Adobe Shockwave Player (12.3.5.205)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234