← Vulnerability feed

Vulnerability record · CVE-2007-6149 · published 13 February 2008

CVE-2007-6149: Adobe connect enterprise server vulnerability

Adobe · Connect Enterprise Server

Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote attackers to execute arbitrary code via a Real Time Message Protocol (RTMP) message with a crafted integer field that is used for allocation.

10.0 CVSS 2.0 High EPSS 12% · top 4.0% CWE-189 · CWE-189
10.0CVSS 2.0 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote attackers to execute arbitrary code via a Real Time Message Protocol (RTMP) message with a crafted integer field that is used for allocation.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-6149 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-2217Adobe flash media server code injection vulnerabilityAdobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to execute arbitrary code via unspecified vectors, related to a…EPSS 4.5%10.0CVE-2007-6148Adobe connect enterprise server vulnerabilityUse-after-free vulnerability in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allows remote…EPSS 8.4%10.0CVE-2007-6431Adobe connect enterprise server vulnerabilityUnspecified vulnerability in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allows remote attackers to "take co…EPSS 4.6%5.0CVE-2010-2218Adobe flash media server vulnerabilityAdobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to cause a denial of service via unspecified vectors, related t…EPSS 2.5%5.0CVE-2010-2219Adobe flash media server vulnerabilityUnspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to cause a denial of service (memo…EPSS 2.5%5.0CVE-2010-2220Adobe flash media server vulnerabilityAdobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to cause a denial of service via unspecified vectors, related t…EPSS 2.5%5.0CVE-2007-4651Adobe connect enterprise server permissions and access controls vulnerabilityUnspecified vulnerability in Adobe Connect Enterprise Server 6 allows remote attackers to read certain pages that are restricted to the administrator…EPSS 2.9%8.4CVE-2013-2094Linux Kernel perf_swevent_init Integer Type Flaw Enables Local Privilege EscalationThe perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, allowing a local user to…KEVEPSS 48%analysed

Source: NIST National Vulnerability Database (record CVE-2007-6149), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.