← Vulnerability feed

Vulnerability record · CVE-2007-6019 · published 9 April 2008

CVE-2007-6019: Adobe Flash Player Actionscript DeclareFunction2 tag memory corruption

Adobe · Air

Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, mishandle a modified DeclareFunction2 Actionscript tag in an SWF file, preventing an object from being instantiated properly. A remote attacker can supply a crafted SWF that triggers memory corruption and arbitrary code execution in the context of the player. The record does not specify the exact memory-safety root cause beyond the malformed tag.

9.3 CVSS 2.0 High EPSS 60% · top 0.9%
9.3CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
44References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with complete impact and a very high EPSS score, but the flaw is in a long-deprecated product and no KEV listing is present.

What it is

Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, mishandle a modified DeclareFunction2 Actionscript tag in an SWF file, preventing an object from being instantiated properly. A remote attacker can supply a crafted SWF that triggers memory corruption and arbitrary code execution in the context of the player. The record does not specify the exact memory-safety root cause beyond the malformed tag.

Impact

Successful exploitation gives the attacker arbitrary code execution with the privileges of the user running Flash Player, which on typical systems means full compromise of that user's session. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

Reached over the network by delivering a malicious SWF file, typically via a web page or embedded content that the victim loads in Flash Player. No authentication is required (Au:N), but the CVSS vector shows medium access complexity (AC:M), implying some condition such as a specific player version or crafted tag layout must be met; user interaction is not stated in the record.

Exploitation

Not listed in CISA KEV, but EPSS is 0.5977 (99.1st percentile), indicating a high modeled likelihood of exploitation activity. A SecurityFocus BID reference carries an Exploit tag, so public exploit information exists, though the record does not describe a weaponized exploit.

What to do

  • Upgrade Flash Player to a version later than 9.0.115.0 / 8.0.39.0 per Adobe bulletin APSB08-11, or remove Flash Player where it is no longer needed.
  • Apply the vendor patches referenced by the Red Hat, openSUSE, Gentoo, Sun and Apple advisories for bundled or platform Flash components.
  • Disable or restrict Flash content in browsers and email clients, and block untrusted SWF files at the gateway where feasible.
  • Enforce least privilege and browser sandboxing so a Flash compromise does not yield broader host control.

Detection

  • Hunt for Flash Player processes spawning unexpected child processes or making anomalous network connections after loading SWF content.
  • Monitor for crashes or memory-corruption events in Flash Player (browser plugin crash reports) tied to SWF loads from untrusted origins.
  • Inspect proxy and web logs for SWF files delivered from unusual or newly seen hosts, especially where Flash is still installed.
  • Use the OVAL definition referenced in the record to check endpoint Flash Player versions against the vulnerable range.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html
http://secunia.com/advisories/29763 Vendor Advisory
http://secunia.com/advisories/29865 Vendor Advisory
http://secunia.com/advisories/30430 Vendor Advisory
http://secunia.com/advisories/30507 Vendor Advisory
http://securityreason.com/securityalert/3805
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1
http://www.adobe.com/support/security/bulletins/apsb08-11.html PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml
http://www.redhat.com/support/errata/RHSA-2008-0221.html
http://www.securityfocus.com/archive/1/490623/100/0/threaded
http://www.securityfocus.com/archive/1/490824/100/0/threaded
http://www.securityfocus.com/bid/28694 ExploitPatch
http://www.securitytracker.com/id?1019810
http://www.us-cert.gov/cas/techalerts/TA08-100A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA08-150A.html US Government Resource
http://www.vupen.com/english/advisories/2008/1697
http://www.vupen.com/english/advisories/2008/1724/references
http://www.zerodayinitiative.com/advisories/ZDI-08-021
https://exchange.xforce.ibmcloud.com/vulnerabilities/41717
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10160
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html
http://secunia.com/advisories/29763 Vendor Advisory
http://secunia.com/advisories/29865 Vendor Advisory
http://secunia.com/advisories/30430 Vendor Advisory
http://secunia.com/advisories/30507 Vendor Advisory
http://securityreason.com/securityalert/3805
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1
http://www.adobe.com/support/security/bulletins/apsb08-11.html PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml
http://www.redhat.com/support/errata/RHSA-2008-0221.html
http://www.securityfocus.com/archive/1/490623/100/0/threaded
http://www.securityfocus.com/archive/1/490824/100/0/threaded
http://www.securityfocus.com/bid/28694 ExploitPatch
http://www.securitytracker.com/id?1019810
http://www.us-cert.gov/cas/techalerts/TA08-100A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA08-150A.html US Government Resource
http://www.vupen.com/english/advisories/2008/1697

Track CVE-2007-6019 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed9.8CVE-2015-3043Adobe Flash Player memory corruption allows arbitrary code executionAdobe Flash Player contains an out-of-bounds write (CWE-787) that corrupts memory and can lead to arbitrary code execution or a denial of service. Th…KEVEPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2007-6019), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.