10
CVE-2017-3060
- EPSS 7.63%
- Veröffentlicht 12.04.2017 14:59:03
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful exploitation could lead to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player SwPlatform edge Version <= 25.0.0.127
Adobe ≫ Flash Player SwPlatform internet_explorer Version <= 25.0.0.127
Adobe ≫ Flash Player SwPlatform chrome Version <= 25.0.0.127
Adobe ≫ Flash Player Version <= 25.0.0.127
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.63% | 0.938 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
http://www.securitytracker.com/id/1038225
https://access.redhat.com/errata/RHSA-2017:0934
https://helpx.adobe.com/security/products/flash-player/apsb17-10.html
https://security.gentoo.org/glsa/201704-04
http://www.securityfocus.com/bid/97557
http://www.zerodayinitiative.com/advisories/ZDI-17-247/