CVE-2017-3002 – flash-plugin: multiple code execution issues fixed in APSB17-07
https://notcve.org/view.php?id=CVE-2017-3002
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability in the ActionScript2 TextField object related to the variable property. Successful exploitation could lead to arbitrary code execution. Adobe Flash Player versión 24.0.0.221 y versiones anteriores tienen una vulnerabilidad de uso después de liberación de memoria explotable en el objeto ActionScript2 TextField relacionado con la propiedad variable. Una explotación exitosa puede resultar en ejecución arbitraria de código. • http://rhn.redhat.com/errata/RHSA-2017-0526.html http://www.securityfocus.com/bid/96861 http://www.securitytracker.com/id/1037994 https://helpx.adobe.com/security/products/flash-player/apsb17-07.html https://security.gentoo.org/glsa/201703-02 https://access.redhat.com/security/cve/CVE-2017-3002 https://bugzilla.redhat.com/show_bug.cgi?id=1432200 • CWE-416: Use After Free •
CVE-2017-3001 – Adobe Flash MovieClip transform Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-3001
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to garbage collection in the ActionScript 2 VM. Successful exploitation could lead to arbitrary code execution. Adobe Flash Player versión 24.0.0.221 y versiones anteriores tienen una vulnerabilidad de uso después de liberación de memoria explotable relacionada con la recolección de basura en la ActionScript 2 VM. Una explotación exitosa puede resultar en ejecución arbitraria de código.. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. • http://rhn.redhat.com/errata/RHSA-2017-0526.html http://www.securityfocus.com/bid/96861 http://www.securitytracker.com/id/1037994 https://helpx.adobe.com/security/products/flash-player/apsb17-07.html https://security.gentoo.org/glsa/201703-02 https://access.redhat.com/security/cve/CVE-2017-3001 https://bugzilla.redhat.com/show_bug.cgi?id=1432200 • CWE-416: Use After Free •
CVE-2017-2998 – flash-plugin: multiple code execution issues fixed in APSB17-07
https://notcve.org/view.php?id=CVE-2017-2998
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK API functionality related to timeline interactions. Successful exploitation could lead to arbitrary code execution. Adobe Flash Player versión 24.0.0.221 y versiones anteriores tienen una vulnerabilidad de corrupción de memoria explotable en la funcionalidad Primetime TVSDK API relacionada con interacciones de la línea del tiempo. Una explotación exitosa podría resultar en ejecución de código arbitrario. • http://rhn.redhat.com/errata/RHSA-2017-0526.html http://www.securityfocus.com/bid/96866 http://www.securitytracker.com/id/1037994 https://helpx.adobe.com/security/products/flash-player/apsb17-07.html https://security.gentoo.org/glsa/201703-02 https://access.redhat.com/security/cve/CVE-2017-2998 https://bugzilla.redhat.com/show_bug.cgi?id=1432200 • CWE-787: Out-of-bounds Write •
CVE-2017-2997 – flash-plugin: multiple code execution issues fixed in APSB17-07
https://notcve.org/view.php?id=CVE-2017-2997
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable buffer overflow / underflow vulnerability in the Primetime TVSDK that supports customizing ad information. Successful exploitation could lead to arbitrary code execution. Adobe Flash Player versión 24.0.0.221 y versiones anteriores tienen una vulnerabilidad de desbordamiento/vaciado de búfer explotable en el Primetime TVSDK que permite personalizar la información del anuncio. Una explotación exitosa puede resultar en ejecución de código arbitrario. • http://rhn.redhat.com/errata/RHSA-2017-0526.html http://www.securityfocus.com/bid/96860 http://www.securitytracker.com/id/1037994 https://helpx.adobe.com/security/products/flash-player/apsb17-07.html https://security.gentoo.org/glsa/201703-02 https://access.redhat.com/security/cve/CVE-2017-2997 https://bugzilla.redhat.com/show_bug.cgi?id=1432200 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-2985 – Adobe Flash - Use-After-Free in Applying Bitmap Filter
https://notcve.org/view.php?id=CVE-2017-2985
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful exploitation could lead to arbitrary code execution. Adobe Flash Player, versiones 24.0.0.194 y anteriores, tienen una vulnerabilidad explotable de uso después de liberación en la clase ActionScript 3 BitmapData. La explotación exitosa podría conducir a la ejecución de código arbitrario. Adobe Flash suffers from a use-after-free vulnerability in applying bitmapfilter. • https://www.exploit-db.com/exploits/41422 http://rhn.redhat.com/errata/RHSA-2017-0275.html http://www.securityfocus.com/bid/96199 http://www.securitytracker.com/id/1037815 https://helpx.adobe.com/security/products/flash-player/apsb17-04.html https://security.gentoo.org/glsa/201702-20 https://access.redhat.com/security/cve/CVE-2017-2985 https://bugzilla.redhat.com/show_bug.cgi?id=1422237 • CWE-416: Use After Free •