{"api_version":"1","generated_at":"2026-07-23T07:17:03+00:00","cve":"CVE-2007-4324","urls":{"html":"https://cve.report/CVE-2007-4324","api":"https://cve.report/api/cve/CVE-2007-4324.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4324","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4324"},"summary":{"title":"CVE-2007-4324","description":"ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not.  NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-08-14 00:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://securitytracker.com/id?1019116","name":"http://securitytracker.com/id?1019116","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Adobe Flash Player Bugs Let Remote Users Execute Arbitrary Code, Scan Ports, and Conduct HTTP Request Splitting and Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0945.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0945.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32448","name":"http://secunia.com/advisories/32448","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat update for flash-plugin - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0980.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0980.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://secunia.com/advisories/32759","name":"http://secunia.com/advisories/32759","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32270","name":"http://secunia.com/advisories/32270","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2008:025","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28213","name":"http://secunia.com/advisories/28213","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE update for flash-player - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11874","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11874","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2007-1126.html","name":"http://www.redhat.com/support/errata/RHSA-2007-1126.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html","name":"http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe - Developer Center : Understanding the security changes in Flash Player 10","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28161","name":"http://secunia.com/advisories/28161","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Adobe Flash Player Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://kb.adobe.com/selfservice/viewContent.do?externalId=kb402956&sliceId=2","name":"http://kb.adobe.com/selfservice/viewContent.do?externalId=kb402956&sliceId=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30507","name":"http://secunia.com/advisories/30507","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sun Solaris update for Adobe Flash Player - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/475961/100/0/threaded","name":"http://www.securityfocus.com/archive/1/475961/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/2995","name":"http://securityreason.com/securityalert/2995","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - ActionScript 3 in Adobe Flash Player 9.0.47.0 socket handling allows port probing","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28570","name":"http://secunia.com/advisories/28570","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo update for netscape-flash - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28157","name":"http://secunia.com/advisories/28157","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat update for flash-plugin - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25260","name":"http://www.securityfocus.com/bid/25260","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe ActionScript SecurityErrorEvent Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-355A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-355A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-355A -- Adobe Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm","name":"http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ASA-2008-440 (RHSA-2008-0980)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/bulletins/apsb08-18.html","name":"http://www.adobe.com/support/security/bulletins/apsb08-18.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe - Security Advisories : APSB08-18: Flash Player update available to address security vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/2838","name":"http://www.vupen.com/english/advisories/2008/2838","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/4258","name":"http://www.vupen.com/english/advisories/2007/4258","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33390","name":"http://secunia.com/advisories/33390","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/1724/references","name":"http://www.vupen.com/english/advisories/2008/1724/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/bulletins/apsb07-20.html","name":"http://www.adobe.com/support/security/bulletins/apsb07-20.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe - Security Advisories : APSB07-20: Flash Player update available to address security vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00007.html","name":"http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Announcement: flash-player (SUSE-SA:20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32702","name":"http://secunia.com/advisories/32702","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat update for flash-plugin - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200801-07.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200801-07.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Adobe Flash Player: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm","name":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ASA-2009-020 (SUN 248586)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=","name":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Nortel: Technical Support: Nortel Response to Sun Alert 248586 - Multiple Security Vulnerabilities in the Flash Player Plugin for Solaris","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://scan.flashsec.org/","name":"http://scan.flashsec.org/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Design flaw in AS3 socket handling allows port probing: Description and PoC of a Flash 9/AS 3 port scanner","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4324","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4324","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4324","vulnerable":"1","versionEndIncluding":"9.0.114.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:53:55.445Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid="},{"name":"SUSE-SA:2007:069","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00007.html"},{"name":"28157","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28157"},{"name":"33390","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33390"},{"name":"2995","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/2995"},{"name":"30507","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30507"},{"name":"oval:org.mitre.oval:def:11874","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11874"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb08-18.html"},{"name":"28570","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28570"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm"},{"name":"32270","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32270"},{"name":"32702","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32702"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html"},{"name":"ADV-2008-1724","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/1724/references"},{"name":"TA07-355A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-355A.html"},{"name":"20070809 Design flaw in AS3 socket handling allows port probing","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/475961/100/0/threaded"},{"name":"GLSA-200801-07","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200801-07.xml"},{"name":"25260","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25260"},{"name":"ADV-2008-2838","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2838"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://scan.flashsec.org/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kb.adobe.com/selfservice/viewContent.do?externalId=kb402956&sliceId=2"},{"name":"28161","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28161"},{"name":"RHSA-2007:1126","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2007-1126.html"},{"name":"32759","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32759"},{"name":"RHSA-2008:0945","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0945.html"},{"name":"238305","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1"},{"name":"RHSA-2008:0980","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0980.html"},{"name":"ADV-2007-4258","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/4258"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm"},{"name":"1019116","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1019116"},{"name":"248586","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1"},{"name":"32448","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32448"},{"name":"SUSE-SR:2008:025","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"},{"name":"28213","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28213"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb07-20.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not.  NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid="},{"name":"SUSE-SA:2007:069","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00007.html"},{"name":"28157","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28157"},{"name":"33390","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33390"},{"name":"2995","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/2995"},{"name":"30507","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30507"},{"name":"oval:org.mitre.oval:def:11874","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11874"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb08-18.html"},{"name":"28570","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28570"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm"},{"name":"32270","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32270"},{"name":"32702","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32702"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html"},{"name":"ADV-2008-1724","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/1724/references"},{"name":"TA07-355A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-355A.html"},{"name":"20070809 Design flaw in AS3 socket handling allows port probing","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/475961/100/0/threaded"},{"name":"GLSA-200801-07","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200801-07.xml"},{"name":"25260","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25260"},{"name":"ADV-2008-2838","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2838"},{"tags":["x_refsource_MISC"],"url":"http://scan.flashsec.org/"},{"tags":["x_refsource_CONFIRM"],"url":"http://kb.adobe.com/selfservice/viewContent.do?externalId=kb402956&sliceId=2"},{"name":"28161","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28161"},{"name":"RHSA-2007:1126","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2007-1126.html"},{"name":"32759","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32759"},{"name":"RHSA-2008:0945","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0945.html"},{"name":"238305","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1"},{"name":"RHSA-2008:0980","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0980.html"},{"name":"ADV-2007-4258","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/4258"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm"},{"name":"1019116","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1019116"},{"name":"248586","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1"},{"name":"32448","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32448"},{"name":"SUSE-SR:2008:025","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"},{"name":"28213","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28213"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb07-20.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4324","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not.  NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=","refsource":"CONFIRM","url":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid="},{"name":"SUSE-SA:2007:069","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00007.html"},{"name":"28157","refsource":"SECUNIA","url":"http://secunia.com/advisories/28157"},{"name":"33390","refsource":"SECUNIA","url":"http://secunia.com/advisories/33390"},{"name":"2995","refsource":"SREASON","url":"http://securityreason.com/securityalert/2995"},{"name":"30507","refsource":"SECUNIA","url":"http://secunia.com/advisories/30507"},{"name":"oval:org.mitre.oval:def:11874","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11874"},{"name":"http://www.adobe.com/support/security/bulletins/apsb08-18.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb08-18.html"},{"name":"28570","refsource":"SECUNIA","url":"http://secunia.com/advisories/28570"},{"name":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm","refsource":"CONFIRM","url":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm"},{"name":"32270","refsource":"SECUNIA","url":"http://secunia.com/advisories/32270"},{"name":"32702","refsource":"SECUNIA","url":"http://secunia.com/advisories/32702"},{"name":"http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html","refsource":"CONFIRM","url":"http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html"},{"name":"ADV-2008-1724","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/1724/references"},{"name":"TA07-355A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-355A.html"},{"name":"20070809 Design flaw in AS3 socket handling allows port probing","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/475961/100/0/threaded"},{"name":"GLSA-200801-07","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200801-07.xml"},{"name":"25260","refsource":"BID","url":"http://www.securityfocus.com/bid/25260"},{"name":"ADV-2008-2838","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2838"},{"name":"http://scan.flashsec.org/","refsource":"MISC","url":"http://scan.flashsec.org/"},{"name":"http://kb.adobe.com/selfservice/viewContent.do?externalId=kb402956&sliceId=2","refsource":"CONFIRM","url":"http://kb.adobe.com/selfservice/viewContent.do?externalId=kb402956&sliceId=2"},{"name":"28161","refsource":"SECUNIA","url":"http://secunia.com/advisories/28161"},{"name":"RHSA-2007:1126","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2007-1126.html"},{"name":"32759","refsource":"SECUNIA","url":"http://secunia.com/advisories/32759"},{"name":"RHSA-2008:0945","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0945.html"},{"name":"238305","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1"},{"name":"RHSA-2008:0980","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0980.html"},{"name":"ADV-2007-4258","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/4258"},{"name":"http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm","refsource":"CONFIRM","url":"http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm"},{"name":"1019116","refsource":"SECTRACK","url":"http://securitytracker.com/id?1019116"},{"name":"248586","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1"},{"name":"32448","refsource":"SECUNIA","url":"http://secunia.com/advisories/32448"},{"name":"SUSE-SR:2008:025","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"},{"name":"28213","refsource":"SECUNIA","url":"http://secunia.com/advisories/28213"},{"name":"http://www.adobe.com/support/security/bulletins/apsb07-20.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb07-20.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4324","datePublished":"2007-08-14T00:00:00.000Z","dateReserved":"2007-08-13T00:00:00.000Z","dateUpdated":"2024-08-07T14:53:55.445Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-14 00:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionEndIncluding":"9.0.114.0","matchCriteriaId":"D0365260-6FAE-4605-BA4F-6F363EA7B565"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4324","Ordinal":"1","Title":"CVE-2007-4324","CVE":"CVE-2007-4324","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4324","Ordinal":"1","NoteData":"ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not.  NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.","Type":"Description","Title":"CVE-2007-4324"},{"CveYear":"2007","CveId":"4324","Ordinal":"2","NoteData":"2007-08-13","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4324","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}