9.3
CVE-2017-3106
- EPSS 22.31%
- Veröffentlicht 11.08.2017 19:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Adobe ≫ Flash Player Desktop Runtime Version <= 26.0.0.137
Adobe ≫ Flash Player SwPlatform edge Version <= 26.0.0.137
Adobe ≫ Flash Player SwPlatform internet_explorer Version <= 26.0.0.137
Adobe ≫ Flash Player SwPlatform chrome Version <= 26.0.0.137
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 22.31% | 0.974 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-704 Incorrect Type Conversion or Cast
The product does not correctly convert an object, resource, or structure from one type to a different type.
http://www.securitytracker.com/id/1039088
https://access.redhat.com/errata/RHSA-2017:2457
https://helpx.adobe.com/security/products/flash-player/apsb17-23.html
https://security.gentoo.org/glsa/201709-16
http://www.securityfocus.com/bid/100190
https://www.exploit-db.com/exploits/42480/