CVE-2007-6244

NameCVE-2007-6244
DescriptionMultiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
flashplugin-nonfreesource(unstable)9.0.115.0.1

Notes

[sarge] - flashplugin-nonfree <no-dsa> (Contrib not supported)
[etch] - flashplugin-nonfree <no-dsa> (Contrib not supported)

Search for package or bug name: Reporting problems