Field Assessment
AI analysis pending.
CVE
CVE-2007-3457
Severity
MEDIUM
CVSS
4.3
EPSS
6.73%
Original Filing — NVD Description
Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.