← All CVEs

CVE-2007-0071

high · 9.3

Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.

9.3
CVSS
92.5%
EPSS (exploit prob.)
100th
EPSS percentile
2008-04-09
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
adobeflash_player>= 8.0, <= 8.0.39.0
adobeflash_player>= 9.0, <= 9.0.115.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-0071