CVE: CVE-2007-2500

Export to Word

server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of SHOWFRAME elements within a DEFINESPRITE element, which triggers memory corruption and enables the attacker to call free with an arbitrary address, probably resultant from a buffer overflow.

Threat-Mapped Scoring

Score: 1.8

Priority: P4 - Informational (Low)

EPSS

Score: 0.13265
Percentile: 0.93829

CVSS Scoring

CVSS v2 Score: 10.0

Severity:

Affected Products

← Back to Home