Skip to content
Saturday, December 6, 2025
Critical Published: Jul 11, 2007 Modified: Apr 09, 2025

CVE-2007-3456

9.3 CVSS SCORE
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
Share:

Description

Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.

CVSS Vector Details

Attack Vector Network
Attack Complexity M
Confidentiality C
Integrity C
Availability C

Affected Software Configurations

  • a adobe flash_player * * * * * * * *
  • a adobe flash_player 9.0.16 * * * * * * *
  • a adobe flash_player 9.0.18d60 * * * * * * *
  • a adobe flash_player 9.0.20 * * * * * * *
  • a adobe flash_player 9.0.20.0 * * * * * * *
  • a adobe flash_player 9.0.28 * * * * * * *
  • a adobe flash_player 9.0.28.0 * * * * * * *
  • a adobe flash_player 9.0.31 * * * * * * *
  • a adobe flash_player 9.0.31.0 * * * * * * *

Weaknesses (CWE)

  • CWE-189

References & External Links