CVE-2007-0071

Severity

93%

Complexity

86%

Confidentiality

165%

Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.

Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.

CVSS 2.0 Base Score 9.3. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).

Overview

First reported 16 years ago

2008-04-09 21:05:00

Last updated 6 years ago

2018-10-30 16:26:00

Affected Software

アドビシステムズ フラッシュプレーヤー

References

http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html

Vendor Advisory

http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf

Broken Link

http://isc.sans.org/diary.html?storyid=4465

Third Party Advisory

APPLE-SA-2008-05-28

Mailing List

SUSE-SA:2008:022

Third Party Advisory

29763

Third Party Advisory

29865

Third Party Advisory

30404

Third Party Advisory

30430

Third Party Advisory

30507

Third Party Advisory

238305

Broken Link

http://www.adobe.com/support/security/bulletins/apsb08-11.html

Vendor Advisory

GLSA-200804-21

Third Party Advisory

20080408 Adobe Flash Player Invalid Pointer Vulnerability

Broken Link

VU#159523

Third Party Advisory, US Government Resource

VU#395473

Third Party Advisory, US Government Resource

http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/

Third Party Advisory

44282

Broken Link

RHSA-2008:0221

Third Party Advisory

28695

Third Party Advisory, VDB Entry

29386

Third Party Advisory, VDB Entry

1019811

Third Party Advisory, VDB Entry

1020114

Third Party Advisory, VDB Entry

TA08-100A

Third Party Advisory, US Government Resource

TA08-149A

Third Party Advisory, US Government Resource

TA08-150A

Third Party Advisory, US Government Resource

ADV-2008-1662

Third Party Advisory

ADV-2008-1697

Third Party Advisory

ADV-2008-1724

Third Party Advisory

http://www.zerodayinitiative.com/advisories/ZDI-08-032/

Third Party Advisory, VDB Entry

multimedia-file-integer-overflow(37277)

Third Party Advisory, VDB Entry

oval:org.mitre.oval:def:10379

Third Party Advisory

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.