CVE-2007-6244
- EPSS 58.43%
- Veröffentlicht 20.12.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigat...
CVE-2007-6245
- EPSS 27.06%
- Veröffentlicht 20.12.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote attackers to modify HTTP headers for client requests and conduct HTTP Request Splitting attacks.
CVE-2007-6246
- EPSS 0.25%
- Veröffentlicht 20.12.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges.
- EPSS 20.64%
- Veröffentlicht 18.10.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9.24 on Mac OS X, has unknown "Highly Severe" impact and unknown attack vectors.
- EPSS 26.09%
- Veröffentlicht 14.08.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (S...
CVE-2007-3456
- EPSS 73.76%
- Veröffentlicht 11.07.2007 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input vali...
CVE-2007-3457
- EPSS 5.85%
- Veröffentlicht 11.07.2007 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.
CVE-2007-2022
- EPSS 15.37%
- Veröffentlicht 13.04.2007 18:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.
- EPSS 18.54%
- Veröffentlicht 17.10.2006 21:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client request...
CVE-2006-3311
- EPSS 57.88%
- Veröffentlicht 12.09.2006 23:07:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.