Page 64 of 453 results (0.016 seconds)

CVSS: 9.3EPSS: 96%CPEs: 9EXPL: 1

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013. Adobe Flash Player anterior a 11.7.700.257y11.8.x y 11.9.x anterior a 11.9.900.170 en Windows y Mac OS X y en Linux antes de 11.2.202.332 , Adobe AIR anterior a AIR3.9.0.1380 , y Adobe AIR SDK y compilador anterior a 3.9.0.1380 permite a atacantes remotos ejecutar código arbitrario a través de contenido swf manipulado que aprovecha un tipo no especificado "type confusion", como se ha explotado en diciembre de 2013. • https://www.exploit-db.com/exploits/33095 http://helpx.adobe.com/security/products/flash-player/apsb13-28.html http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.html http://lists.opensuse.org/opensuse-updates/2013-12/msg00075.html http://lists.opensuse.org/opensuse-updates/2013-12/msg00084.html http://rhn.redhat.com/errata/RHSA-2013-1818.html https://access.redhat.com/security/cve/CVE-2013-5331 https://bugzilla.redhat.com/show_bug.cgi?id=1040185 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 9.3EPSS: 2%CPEs: 9EXPL: 0

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. Adobe Flash Player anterior a 11.7.700.257 y 11.8.x y 11.9.x antes 11.9.900.170 en Windows y Mac OS X y antes de 11.2.202.332 en Linux, Adobe AIR 3.9.0.1380 antes, Adobe AIR SDK 3.9.0.1380 antes, y Adobe AIR SDK y compilador antes 3.9.0.1380 permite a un atacante ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) a través de vectores no especificados. • http://helpx.adobe.com/security/products/flash-player/apsb13-28.html http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.html http://lists.opensuse.org/opensuse-updates/2013-12/msg00075.html http://lists.opensuse.org/opensuse-updates/2013-12/msg00084.html http://rhn.redhat.com/errata/RHSA-2013-1818.html https://access.redhat.com/security/cve/CVE-2013-5332 https://bugzilla.redhat.com/show_bug.cgi?id=1040185 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 10.0EPSS: 7%CPEs: 9EXPL: 0

Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330. Adobe Flash Player anterior a 11.7.700.252 y 11.8.x y 11.9.x anterior a 11.9.900.152 en Windows y Mac OS X y anteriores a 11.2.202.327 en Linux, Adobe AIR anterior a 3.9.0.1210 , Adobe AIR SDK anteror a 3.9.0.1210 y Adobe AIR SDK y compilador antes 3.9.0.1210 permite a los atacantes ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) a través de vectores no especificados, una vulnerabilidad diferente a CVE-2013-5.330 • http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.html http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.html http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.html http://rhn.redhat.com/errata/RHSA-2013-1518.html http://www.adobe.com/support/security/bulletins/apsb13-26.html https://access.redhat.com/security/cve/CVE-2013-5329 https://bugzilla.redhat.com/show_bug.cgi?id=1029692 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 10.0EPSS: 19%CPEs: 9EXPL: 0

Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329. Adobe Flash Player anterior a 11.7.700.252 y 11.8.x y 11.9.x anterior a 11.9.900.152 en Windows y Mac OS X y anteriores a 11.2.202.327 en Linux, Adobe AIR anterior a 3.9.0.1210 , Adobe AIR SDK anteror a 3.9.0.1210 y Adobe AIR SDK y compilador antes 3.9.0.1210 permite a los atacantes ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) a través de vectores no especificados, una vulnerabilidad diferente a CVE-2013-5.329. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within processing of certain AVM2 instructions, allowing direct memory access outside of the domain memory. By leveraging this flaw, an attacker can execute arbitrary code in the context of the current process. • http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.html http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.html http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.html http://rhn.redhat.com/errata/RHSA-2013-1518.html http://www.adobe.com/support/security/bulletins/apsb13-26.html https://access.redhat.com/security/cve/CVE-2013-5330 https://bugzilla.redhat.com/show_bug.cgi?id=1029692 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 10.0EPSS: 7%CPEs: 13EXPL: 0

Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3362, CVE-2013-3363, and CVE-2013-5324. Adobe Flash Player anterior a 11.7.700.242 y 11.8.x anterior a 11.8.800.168 en Windows y Mac OS X, anterior a 11.2.202.310 en Linux, anterior a 11.1.111.73 en Android 2.x y 3.x, y anteriores, 11.1.115.81 en Android 4.x; Adobe AIR anterior a 3.8.0.1430; y Adobe AIR SDK & Compiler anterior a 3.8.0.1430 permite a atacantes ejecutar código arbitrario o causar denegación de servicio (corrupción de memoria) a través de vectores sin especificar. Vulnerabilidad diferente a CVE-2013-3362, CVE-2013-3363, and CVE-2013-5324. • http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00001.html http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00002.html http://lists.opensuse.org/opensuse-updates/2013-09/msg00040.html http://rhn.redhat.com/errata/RHSA-2013-1256.html http://www.adobe.com/support/security/bulletins/apsb13-21.html https://access.redhat.com/security/cve/CVE-2013-3361 https://bugzilla.redhat.com/show_bug.cgi?id=1006496 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •