CVE-2007-6019

Description

Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
66.216

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe flash player 9.0.48.0 to latest versionWindows
Upgrade air 1.0 to latest versionWindows
Multiple vulnerabilities affected in Adobe Flash Player Plugin 9.0.48.0Windows
Multiple vulnerabilities affected in Adobe Flash Player PPAPI 9.0.48.0Windows
Vulnerability CVE-2007-6019 are affected in Adobe Flash Player 11 ActiveX 9.0.155.0Windows
Multiple Vulnerabilities are affected in Adobe AIR For Mac 1.0Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234