CVE-2007-6243 : Dettaglio

CVE-2007-6243

A01-Broken Access Control
38.89%V4
Network
2007-12-20
01h00 +00:00
2024-08-07
16h02 +00:00
Notifiche per una CVE specifica
Rimani informato su qualsiasi modifica relativa a una CVE specifica.
Gestione notifiche

Descrizioni CVE

Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.

Informazioni CVE

Vulnerabilità correlate

CWE-ID Nome della vulnerabilità Source
CWE-264 Category : Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Metriche

Metriche Punteggio Gravità CVSS Vettore Source
V2 9.3 AV:N/AC:M/Au:N/C:C/I:C/A:C nvd@nist.gov

EPSS

EPSS è un modello di punteggio che prevede la probabilità che una vulnerabilità venga sfruttata.

Punteggio EPSS

Il modello EPSS produce un punteggio di probabilità compreso tra 0 e 1 (da 0 a 100%). Più alto è il punteggio, maggiore è la probabilità che una vulnerabilità venga sfruttata.

Percentile EPSS

Il percentile viene utilizzato per classificare le CVE in base al loro punteggio EPSS. Ad esempio, una CVE al 95° percentile secondo il suo punteggio EPSS ha una probabilità maggiore di essere sfruttata rispetto al 95% delle altre CVE. Il percentile consente quindi di confrontare il punteggio EPSS di una CVE con quello delle altre.

Products Mentioned

Configuraton 0

Adobe>>Flash_player >> Version To (including) 9.0.48.0

Riferimenti

http://secunia.com/advisories/29865
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/33390
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/30507
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/28570
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/32702
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.us-cert.gov/cas/techalerts/TA07-355A.html
Tags : third-party-advisory, x_refsource_CERT
http://www.gentoo.org/security/en/glsa/glsa-200801-07.xml
Tags : vendor-advisory, x_refsource_GENTOO
http://www.redhat.com/support/errata/RHSA-2008-0221.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.us-cert.gov/cas/techalerts/TA08-150A.html
Tags : third-party-advisory, x_refsource_CERT
http://jvn.jp/jp/JVN%2345675516/index.html
Tags : third-party-advisory, x_refsource_JVN
http://www.kb.cert.org/vuls/id/935737
Tags : third-party-advisory, x_refsource_CERT-VN
http://secunia.com/advisories/30430
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.securityfocus.com/bid/26929
Tags : vdb-entry, x_refsource_BID
http://secunia.com/advisories/28161
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/32759
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/29763
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.redhat.com/support/errata/RHSA-2008-0945.html
Tags : vendor-advisory, x_refsource_REDHAT
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1
Tags : vendor-advisory, x_refsource_SUNALERT
http://www.redhat.com/support/errata/RHSA-2008-0980.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.vupen.com/english/advisories/2007/4258
Tags : vdb-entry, x_refsource_VUPEN
http://securitytracker.com/id?1019116
Tags : vdb-entry, x_refsource_SECTRACK
http://www.securityfocus.com/bid/26966
Tags : vdb-entry, x_refsource_BID
http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml
Tags : vendor-advisory, x_refsource_GENTOO
http://www.vupen.com/english/advisories/2008/1697
Tags : vdb-entry, x_refsource_VUPEN
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
Tags : vendor-advisory, x_refsource_SUNALERT
http://secunia.com/advisories/32448
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.us-cert.gov/cas/techalerts/TA08-100A.html
Tags : third-party-advisory, x_refsource_CERT
http://secunia.com/advisories/28213
Tags : third-party-advisory, x_refsource_SECUNIA