CVE-2007-6637

Description

Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to pre-generated SWF files and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.

Risk Information

Base Score
6.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
44.771

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe flash player 9.0.48.0 to latest versionWindows
Multiple vulnerabilities affected in Adobe Flash Player Plugin 9.0.48.0Windows
Multiple vulnerabilities affected in Adobe Flash Player PPAPI 9.0.48.0Windows
Vulnerability CVE-2007-0071,CVE-2007-6637,CVE-2008-1655 are affected in Adobe Flash Player 11 ActiveX 9.0.115.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234