9.3

CVE-2007-0071

Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
AdobeFlash Player Version >= 8.0 <= 8.0.39.0
AdobeFlash Player Version >= 9.0 <= 9.0.115.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 89.43% 0.995
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
http://www.us-cert.gov/cas/techalerts/TA08-150A.html
Third Party Advisory
US Government Resource
http://www.us-cert.gov/cas/techalerts/TA08-100A.html
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/159523
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/395473
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/28695
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/29386
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1019811
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1020114
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA08-149A.html
Third Party Advisory
US Government Resource