9.3
CVE-2020-9746
- EPSS 1.72%
- Veröffentlicht 14.10.2020 14:15:17
- Zuletzt bearbeitet 21.11.2024 05:41:12
- Quelle psirt@adobe.com
- CVE-Watchlists
- Unerledigt
Exploitable NULL pointer deref could lead to arbitrary code execution
Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version <= 32.0.0.433
Adobe ≫ Flash Player SwPlatformchrome Version < 32.0.0.433
Adobe ≫ Flash Player SwPlatformedge Version < 32.0.0.387
Adobe ≫ Flash Player SwPlatforminternet_explorer_11 Version < 32.0.0.387
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.72% | 0.819 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
| psirt@adobe.com | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.