CVE-2007-6019
Adobe Flash Player DeclareFunction2 Invalid Object Use Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
Adobe Flash Player 9.0.115.0 y versiones anteriores, y 8.0.39.0 y versiones anteriores, permite a atacantes remotos ejecutar código de su elección a través de un fichero SWF con una etiqueta modificada DeclareFunction2 Actionscript, lo cual evita que un objeto sea instanciado adecuadamente.
This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe's Flash Player. User interaction is required in that a user must visit a malicious web site.
The specific flaw exists when the Flash player attempts to access embedded Actionscript objects that have not been properly instantiated. In order for exploitation to occur, an attacker would have to modify a DeclareFunction2 Actionscript tag within an SWF file. Exploitation of this vulnerability can result in arbitrary code execution under the context of the currently logged in user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-11-19 CVE Reserved
- 2008-04-08 CVE Published
- 2008-04-08 First Exploit
- 2024-08-07 CVE Updated
- 2024-10-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (25)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/3805 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/490623/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/490824/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1019810 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA08-100A.html | Third Party Advisory | |
http://www.us-cert.gov/cas/techalerts/TA08-150A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2008/1697 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1724/references | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-08-021 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41717 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10160 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31630 | 2008-04-08 | |
http://www.securityfocus.com/bid/28694 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://www.adobe.com/support/security/bulletins/apsb08-11.html | 2018-10-30 |
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html | 2018-10-30 | |
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html | 2018-10-30 | |
http://secunia.com/advisories/29763 | 2018-10-30 | |
http://secunia.com/advisories/29865 | 2018-10-30 | |
http://secunia.com/advisories/30430 | 2018-10-30 | |
http://secunia.com/advisories/30507 | 2018-10-30 | |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1 | 2018-10-30 | |
http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml | 2018-10-30 | |
http://www.redhat.com/support/errata/RHSA-2008-0221.html | 2018-10-30 | |
https://access.redhat.com/security/cve/CVE-2007-6019 | 2008-04-08 | |
https://bugzilla.redhat.com/show_bug.cgi?id=440683 | 2008-04-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Air Search vendor "Adobe" for product "Air" | 1.0 Search vendor "Adobe" for product "Air" and version "1.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Search vendor "Adobe" for product "Flash" | basic Search vendor "Adobe" for product "Flash" and version "basic" | 8 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Search vendor "Adobe" for product "Flash" | professional Search vendor "Adobe" for product "Flash" and version "professional" | 8 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Search vendor "Adobe" for product "Flash" | professional Search vendor "Adobe" for product "Flash" and version "professional" | cs3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 9.0.115.0 Search vendor "Adobe" for product "Flash Player" and version " <= 9.0.115.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0 Search vendor "Adobe" for product "Flash Player" and version "7.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.1 Search vendor "Adobe" for product "Flash Player" and version "7.0.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.25 Search vendor "Adobe" for product "Flash Player" and version "7.0.25" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.63 Search vendor "Adobe" for product "Flash Player" and version "7.0.63" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.69.0 Search vendor "Adobe" for product "Flash Player" and version "7.0.69.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0.70.0 Search vendor "Adobe" for product "Flash Player" and version "7.0.70.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.0_r67 Search vendor "Adobe" for product "Flash Player" and version "7.0_r67" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.1 Search vendor "Adobe" for product "Flash Player" and version "7.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.1.1 Search vendor "Adobe" for product "Flash Player" and version "7.1.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 7.2 Search vendor "Adobe" for product "Flash Player" and version "7.2" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8 Search vendor "Adobe" for product "Flash Player" and version "8" | pro |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8 Search vendor "Adobe" for product "Flash Player" and version "8" | professional |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0 Search vendor "Adobe" for product "Flash Player" and version "8.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0 Search vendor "Adobe" for product "Flash Player" and version "8.0" | basic |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0 Search vendor "Adobe" for product "Flash Player" and version "8.0" | pro |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0.24.0 Search vendor "Adobe" for product "Flash Player" and version "8.0.24.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0.34.0 Search vendor "Adobe" for product "Flash Player" and version "8.0.34.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0.35.0 Search vendor "Adobe" for product "Flash Player" and version "8.0.35.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 8.0.39.0 Search vendor "Adobe" for product "Flash Player" and version "8.0.39.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0 Search vendor "Adobe" for product "Flash Player" and version "9.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.16 Search vendor "Adobe" for product "Flash Player" and version "9.0.16" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.16 Search vendor "Adobe" for product "Flash Player" and version "9.0.16" | windows |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.18d60 Search vendor "Adobe" for product "Flash Player" and version "9.0.18d60" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.20 Search vendor "Adobe" for product "Flash Player" and version "9.0.20" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.20.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.20.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.28 Search vendor "Adobe" for product "Flash Player" and version "9.0.28" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.28.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.28.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.31 Search vendor "Adobe" for product "Flash Player" and version "9.0.31" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.31.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.31.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.45.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.45.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.47.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.47.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.48.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.48.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.112.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.112.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.114.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.114.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.124.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.124.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 9.0.155.0 Search vendor "Adobe" for product "Flash Player" and version "9.0.155.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flex Search vendor "Adobe" for product "Flex" | 3.0 Search vendor "Adobe" for product "Flex" and version "3.0" | - |
Affected
|