CVE-2007-3456
Adobe Flash Player < 9.0.45.0 - Remote Code Execution via Large Length Value in FLV or SWF File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3456. PoCs published by Stefano DiPaola.
AI-analyzed exploit summary This is a vulnerability writeup for CVE-2007-3456, describing a remote code execution flaw in Adobe Flash Player due to improper input sanitization. The writeup references a binary exploit but does not contain actual exploit code.
Description
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.
Exploits (1)
This is a vulnerability writeup for CVE-2007-3456, describing a remote code execution flaw in Adobe Flash Player due to improper input sanitization. The writeup references a binary exploit but does not contain actual exploit code.