CVE Vulnerabilities

CVE-2007-6243

Published: Dec 20, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.

Affected Software

NameVendorStart VersionEnd Version
Flash_playerAdobe*9.0.48.0 (including)
Extras for RHEL 3RedHatflash-plugin-0:9.0.115.0-1.el3.with.oss*
Extras for RHEL 3RedHatflash-plugin-0:9.0.124.0-1.el3.with.oss*
Extras for RHEL 3RedHatflash-plugin-0:9.0.151.0-1.el3.with.oss*
Extras for RHEL 4RedHatflash-plugin-0:9.0.115.0-1.el4*
Extras for RHEL 4RedHatflash-plugin-0:9.0.124.0-1.el4*
Extras for RHEL 4RedHatflash-plugin-0:9.0.151.0-1.el4*
Supplementary for Red Hat Enterprise Linux 5RedHatflash-plugin-0:9.0.115.0-1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatflash-plugin-0:9.0.124.0-1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatflash-plugin-0:10.0.12.36-2.el5*
Flashplugin-nonfreeUbuntudapper*
Flashplugin-nonfreeUbuntuedgy*
Flashplugin-nonfreeUbuntufeisty*
Flashplugin-nonfreeUbuntugutsy*
Flashplugin-nonfreeUbuntuupstream*

References