CVE-2017-3060 – Adobe Flash SWF Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2017-3060
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Flash Player 25.0.0.127 y anteriores tienen una vulnerabilidad de corrupción de memoria explotable en el analizador de código ActionScript2. Una explotación exitosa podría conducir a la ejecución arbitraria de código. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. • http://www.securityfocus.com/bid/97557 http://www.securitytracker.com/id/1038225 http://www.zerodayinitiative.com/advisories/ZDI-17-247 https://access.redhat.com/errata/RHSA-2017:0934 https://helpx.adobe.com/security/products/flash-player/apsb17-10.html https://security.gentoo.org/glsa/201704-04 https://access.redhat.com/security/cve/CVE-2017-3060 https://bugzilla.redhat.com/show_bug.cgi?id=1441308 • CWE-125: Out-of-bounds Read •
CVE-2017-3062 – Adobe Flash TextField Attribute Array Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-3062
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Flash Player 25.0.0.127 y anteriores tienen un uso explotable después de la vulnerabilidad gratuita en ActionScript2 al crear una propiedad getter/setter. Una explotación exitosa podría conducir a la ejecución arbitraria de código. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. • http://www.securityfocus.com/bid/97551 http://www.securitytracker.com/id/1038225 http://www.zerodayinitiative.com/advisories/ZDI-17-278 https://access.redhat.com/errata/RHSA-2017:0934 https://helpx.adobe.com/security/products/flash-player/apsb17-10.html https://security.gentoo.org/glsa/201704-04 https://access.redhat.com/security/cve/CVE-2017-3062 https://bugzilla.redhat.com/show_bug.cgi?id=1441308 • CWE-416: Use After Free •
CVE-2017-2997 – flash-plugin: multiple code execution issues fixed in APSB17-07
https://notcve.org/view.php?id=CVE-2017-2997
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable buffer overflow / underflow vulnerability in the Primetime TVSDK that supports customizing ad information. Successful exploitation could lead to arbitrary code execution. Adobe Flash Player versión 24.0.0.221 y versiones anteriores tienen una vulnerabilidad de desbordamiento/vaciado de búfer explotable en el Primetime TVSDK que permite personalizar la información del anuncio. Una explotación exitosa puede resultar en ejecución de código arbitrario. • http://rhn.redhat.com/errata/RHSA-2017-0526.html http://www.securityfocus.com/bid/96860 http://www.securitytracker.com/id/1037994 https://helpx.adobe.com/security/products/flash-player/apsb17-07.html https://security.gentoo.org/glsa/201703-02 https://access.redhat.com/security/cve/CVE-2017-2997 https://bugzilla.redhat.com/show_bug.cgi?id=1432200 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-2998 – flash-plugin: multiple code execution issues fixed in APSB17-07
https://notcve.org/view.php?id=CVE-2017-2998
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK API functionality related to timeline interactions. Successful exploitation could lead to arbitrary code execution. Adobe Flash Player versión 24.0.0.221 y versiones anteriores tienen una vulnerabilidad de corrupción de memoria explotable en la funcionalidad Primetime TVSDK API relacionada con interacciones de la línea del tiempo. Una explotación exitosa podría resultar en ejecución de código arbitrario. • http://rhn.redhat.com/errata/RHSA-2017-0526.html http://www.securityfocus.com/bid/96866 http://www.securitytracker.com/id/1037994 https://helpx.adobe.com/security/products/flash-player/apsb17-07.html https://security.gentoo.org/glsa/201703-02 https://access.redhat.com/security/cve/CVE-2017-2998 https://bugzilla.redhat.com/show_bug.cgi?id=1432200 • CWE-787: Out-of-bounds Write •
CVE-2017-2999 – flash-plugin: multiple code execution issues fixed in APSB17-07
https://notcve.org/view.php?id=CVE-2017-2999
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK functionality related to hosting playback surface. Successful exploitation could lead to arbitrary code execution. Adobe Flash Player versión 24.0.0.221 y versiones anteriores tienen una vulnerabilidad de corrupción de memoria explotable en la funcionalidad Primetime TVSDK relacionada con alojamiento de la superficie de reproducción. Una explotación exitosa podría resultar en ejecución de código arbitrario. • http://rhn.redhat.com/errata/RHSA-2017-0526.html http://www.securityfocus.com/bid/96866 http://www.securitytracker.com/id/1037994 https://helpx.adobe.com/security/products/flash-player/apsb17-07.html https://security.gentoo.org/glsa/201703-02 https://access.redhat.com/security/cve/CVE-2017-2999 https://bugzilla.redhat.com/show_bug.cgi?id=1432200 • CWE-787: Out-of-bounds Write •