Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-6637
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-6637

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.

CVE Status:
Candidate

References:

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1

ST
  1019141

SAID
  Secunia Advisory: SA29763
  Secunia Advisory: SA29865
  Secunia Advisory: SA30430
  Secunia Advisory: SA30507

REDHAT
  http://www.redhat.com/support/errata/RHSA-2008-0221.html

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml

CONFIRM
  http://www.adobe.com/support/security/bulletins/apsb08-11.html
  http://www.adobe.com/support/security/advisories/apsa07-06.html

CERT
  http://www.us-cert.gov/cas/techalerts/TA08-150A.html
  http://www.us-cert.gov/cas/techalerts/TA08-100A.html

BID
  27034

APPLE
  http://lists.apple.com/archives/security-announce/2008//May/msg00001.html


Return to the previous page.