PublicDate: 2008-01-04 00:46:00 UTC Candidate: CVE-2007-6637 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6637 Description: Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_flashplugin-nonfree: upstream_flashplugin-nonfree: needs-triage dapper_flashplugin-nonfree: ignored (reached end-of-life) edgy_flashplugin-nonfree: needed (reached end-of-life) feisty_flashplugin-nonfree: needed (reached end-of-life) gutsy_flashplugin-nonfree: needed (reached end-of-life) hardy_flashplugin-nonfree: released (9.0.246.0ubuntu1) intrepid_flashplugin-nonfree: released (10.0.32.18ubuntu0.8.10.1) jaunty_flashplugin-nonfree: released (10.0.32.18ubuntu0.9.04.1) karmic_flashplugin-nonfree: released (10.0.32.18ubuntu1) devel_flashplugin-nonfree: released (10.0.32.18ubuntu1)