CVE-2007-6637 describes multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player, specifically when processing crafted SWF files, including those generated by Adobe Dreamweaver CS3 or Adobe Acrobat Connect. This vulnerability has a CVSS score of 4.3, indicating a medium severity, as it requires user interaction (medium attack complexity) but can lead to information disclosure (partial impact to integrity). While the FAUCET Risk Score is high at 93/100, there is no evidence of active exploitation, no known public exploit code, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.25CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0.25:*:*:*:*:*:*:* | ||
7.0.63CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0.63:*:*:*:*:*:*:* | ||
7.0.69.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0.69.0:*:*:*:*:*:*:* | ||
7.0.70.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0.70.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.