10

CVE-2017-3114

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version <= 27.0.0.183
   Apple ≫ macOS Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player SwPlatform chrome Version <= 27.0.0.183
   Apple ≫ macOS Version -
   Google ≫ Chrome Os Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player SwPlatform edge Version <= 27.0.0.183
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 8.1 Version -
Adobe ≫ Flash Player SwPlatform intenet_explorer_11 Version <= 27.0.0.183
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 8.1 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.22% 0.926
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

http://www.securityfocus.com/bid/101837
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1039778
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2017:3222
Third Party Advisory
VDB Entry
https://helpx.adobe.com/security/products/flash-player/apsb17-33.html
Patch
Vendor Advisory
https://security.gentoo.org/glsa/201711-13
Third Party Advisory
VDB Entry