CVE-2007-2500

10.0
CVSS v2.0 Base Score
5.39%
LOW RiskEPSS (92nd percentile)
NVD-CWE-Other

server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of SHOWFRAME elements within a DEFINESPRITE element, which triggers memory corruption and enables the attacker to call free with an arbitrary address, probably resultant from a buffer overflow.

Published: 5/4/2007
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

10

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

5.39%LOW Exploitation Risk
92nd percentile

This vulnerability has a 5.39% probability of being exploited in the next 30 days, ranking higher than 92% of all scored CVEs.

CWE Classification

NVD-CWE-Other
Advertisement