CVE-2007-6637: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6637?
CVE-2007-6637 is rated as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2007-6637?
To fix CVE-2007-6637, users should upgrade to the latest version of Adobe Flash Player that addresses the identified vulnerabilities.
What types of attacks does CVE-2007-6637 facilitate?
CVE-2007-6637 facilitates cross-site scripting (XSS) attacks, allowing remote attackers to inject arbitrary web scripts or HTML.
Which Adobe Flash Player versions are affected by CVE-2007-6637?
CVE-2007-6637 affects multiple versions of Adobe Flash Player including 7.0.25, 7.0.63, 8.0, and 9.0.x versions.
Can CVE-2007-6637 be exploited without user interaction?
Yes, CVE-2007-6637 can be exploited without user interaction if a user visits a malicious site hosting a crafted SWF file.