← All CVEs

CVE-2007-6019

high · 9.3

Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.

9.3
CVSS
59.8%
EPSS (exploit prob.)
99th
EPSS percentile
2008-04-09
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
adobeair1.0
adobeflashbasic
adobeflashprofessional
adobeflashprofessional
adobeflash_player<= 9.0.115.0
adobeflash_player7.0
adobeflash_player7.0.1
adobeflash_player7.0.25
adobeflash_player7.0.63
adobeflash_player7.0.69.0
adobeflash_player7.0.70.0
adobeflash_player7.0_r67
adobeflash_player7.1
adobeflash_player7.1.1
adobeflash_player7.2
adobeflash_player8
adobeflash_player8
adobeflash_player8.0
adobeflash_player8.0
adobeflash_player8.0
adobeflash_player8.0.24.0
adobeflash_player8.0.34.0
adobeflash_player8.0.35.0
adobeflash_player8.0.39.0
adobeflash_player9.0
adobeflash_player9.0.16
adobeflash_player9.0.16
adobeflash_player9.0.18d60
adobeflash_player9.0.20
adobeflash_player9.0.20.0
adobeflash_player9.0.28
adobeflash_player9.0.28.0
adobeflash_player9.0.31
adobeflash_player9.0.31.0
adobeflash_player9.0.45.0
adobeflash_player9.0.47.0
adobeflash_player9.0.48.0
adobeflash_player9.0.112.0
adobeflash_player9.0.114.0
adobeflash_player9.0.124.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-6019