Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2007-3456

Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.

  • Published: Jul 11, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-3456
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 9.3
  • AV:N/AC:M/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
adobe / flash_player - 9.0.45.0.x
adobe / flash_player 9.0.18d60 9.0.18d60.x
adobe / flash_player 9.0.20.0 9.0.20.0.x
adobe / flash_player 9.0.31.0 9.0.31.0.x
adobe / flash_player 9.0.16 9.0.16.x
adobe / flash_player 9.0.28.0 9.0.28.0.x
adobe / flash_player 9.0.28 9.0.28.x
adobe / flash_player 9.0.31 9.0.31.x
adobe / flash_player 9.0.20 9.0.20.x