CVE-2007-0071
47Vexday Risk Score
Prioriza la corrección. Ella explotación observada por VulnCheck.
ssvc Actepss 93%
de la publicación al arma
Publicada en NVD9 abr
VulnCheck+49d
probabilidad de explotación
93%top 1% de las CVE
explotación observada
síVulnCheck
Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.
Productos afectados
n/a · n/aReferencias
http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.htmlhttp://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdfhttp://isc.sans.org/diary.html?storyid=4465http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.htmlhttp://secunia.com/advisories/29763http://secunia.com/advisories/29865http://secunia.com/advisories/30404http://secunia.com/advisories/30430http://secunia.com/advisories/30507https://exchange.xforce.ibmcloud.com/vulnerabilities/37277https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10379