CVE-2007-4324 describes a security sandbox bypass vulnerability in Adobe Flash Player versions 9.0.47.0 and earlier, including 9.0.124.0, affecting ActionScript 3 (AS3). Remote attackers could exploit this by crafting a Flash movie to perform port scanning on arbitrary hosts and obtain sensitive information by analyzing timing discrepancies from SecurityErrorEvent errors. With a CVSS score of 5.0 (medium severity), this vulnerability has a low attack complexity and requires no authentication, primarily impacting confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0.114.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.