Page 15 of 145 results (0.004 seconds)

CVSS: 9.8EPSS: 4%CPEs: 46EXPL: 0

10 Dec 2009 — Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. Múltiples vulnerabilidades sin especificar en Adobe Flash Player anteriores a v10.0.42.34 y Adobe AIR anteriores a v1.5.3 permite a atacantes producir una denegación de servicio (caída de aplicación) o posiblemente ejecutar código arbitrario a través de vectores desconocidos. • http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html •

CVSS: 9.1EPSS: 6%CPEs: 48EXPL: 0

10 Dec 2009 — Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820. Vulnerabilidad sin especificar en el control ActiveX de Flash Player en Adobe Flash Player en versiones anteriores a v10.0.42.34 y Adobe AIR anteriores a v1.5.3 en Windows permite a atacantes remotos obtener los ... • http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.3EPSS: 8%CPEs: 46EXPL: 0

09 Dec 2009 — Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file. Desbordamiento del búfer de la pila en Adobe Flash Player anteriores a v10.0.42.34 y Adobe AIR anteriores a v1.5.3 permite a atacantes remotos ejecutar código arbitrario a través de las dimensiones manipuladas de datos JPEG en un fichero SWF. This vulnerability allows remote attackers to execute arbitrary code on v... • http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.8EPSS: 12%CPEs: 46EXPL: 0

09 Dec 2009 — Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers." Desbordamiento de entero en la funcion Verifier::parseExceptionHandlers en Adobe Flash Player anteriores a v10.0.42.34 y Adobe AIR anteriores a v1.5.3 permite a atacantes remotos ejecut... • http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html • CWE-189: Numeric Errors •

CVSS: 9.8EPSS: 2%CPEs: 2EXPL: 0

17 Nov 2008 — Unspecified vulnerability in Adobe AIR 1.1 and earlier allows context-dependent attackers to execute untrusted JavaScript in an AIR application via unknown attack vectors. Vulnerabilidad sin especificar en Adobe AIR 1.1 y anteriores permite ejecutar código JavaScript no confiable a atacantes locales o remotos dependiendo del contexto en una aplicación AIR a través de vectores de ataque desconocidos. • http://osvdb.org/49915 • CWE-94: Improper Control of Generation of Code ('Code Injection') •