CVE-2007-6243
Last modified
CVE-2007-6243 is a vulnerability of currently unknown severity. Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.. EPSS estimates a 8.47% chance of exploitation in the next 30 days.
Description
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | <= 9.0.48.0 |
References
- http://secunia.com/advisories/28213Vendor Advisory
- http://secunia.com/advisories/29763Vendor Advisory
- http://secunia.com/advisories/29865Vendor Advisory
- http://secunia.com/advisories/30430Vendor Advisory
- http://secunia.com/advisories/30507Vendor Advisory
- http://secunia.com/advisories/32448Vendor Advisory
- http://secunia.com/advisories/32702Vendor Advisory
- http://secunia.com/advisories/32759Vendor Advisory
- http://secunia.com/advisories/33390Vendor Advisory
- http://www.kb.cert.org/vuls/id/935737US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-355A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA08-100A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlUS Government Resource
- http://secunia.com/advisories/28213Vendor Advisory
- http://secunia.com/advisories/29763Vendor Advisory
- http://secunia.com/advisories/29865Vendor Advisory
- http://secunia.com/advisories/30430Vendor Advisory
- http://secunia.com/advisories/30507Vendor Advisory
- http://secunia.com/advisories/32448Vendor Advisory
- http://secunia.com/advisories/32702Vendor Advisory
- http://secunia.com/advisories/32759Vendor Advisory
- http://secunia.com/advisories/33390Vendor Advisory
- http://www.kb.cert.org/vuls/id/935737US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-355A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA08-100A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6243?
How severe is CVE-2007-6243?
How do I fix CVE-2007-6243?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6237cp.php in DeluxeBB 1.09 does not verify that the membercooki…
- CVE-2007-6238Unspecified vulnerability in Apple QuickTime 7.2 on Windows …
- CVE-2007-6239The "cache update reply processing" functionality in Squid 2…
- CVE-2007-6240SQL injection vulnerability in active.asp in Snitz Forums 20…
- CVE-2007-6241Multiple unspecified vulnerabilities in Beehive Forum 0.7.1 …
- CVE-2007-6242Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and…
- CVE-2007-6244Multiple cross-site scripting (XSS) vulnerabilities in Adobe…
- CVE-2007-6245Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, a…
- CVE-2007-6246Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, a…
- CVE-2007-6247Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-6249etc-update in Portage before 2.1.3.11 on Gentoo Linux relies…
- CVE-2007-6250Stack-based buffer overflow in AOL AOLMediaPlaybackControl (…
Are you affected by CVE-2007-6243?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
