Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-3062

Опубликовано: 12 апр. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10
CVSS3: 9.8

Описание

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:20170509.1-0ubuntu0.14.04.1]]
precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

released

1:20170509.1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1:20170509.1-0ubuntu0.14.04.1]
upstream

released

25.0.0.148
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

released

1:20170509.1-0ubuntu0.16.04.1

Показывать по

РелизСтатусПримечание
devel

released

25.0.0.171ubuntu1
esm-apps/xenial

released

25.0.0.171ubuntu0.16.04.1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [25.0.0.171ubuntu0.14.04.1]]
precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

released

25.0.0.171ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [25.0.0.171ubuntu0.14.04.1]
upstream

released

25.0.0.148
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

EPSS

Процентиль: 89%
0.04446
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
почти 9 лет назад

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
nvd
почти 9 лет назад

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
github
больше 3 лет назад

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution.

fstec
почти 9 лет назад

Уязвимость программной платформы Flash Player, позволяющая нарушителю выполнить произвольный код

suse-cvrf
почти 9 лет назад

Security update for flash-player

EPSS

Процентиль: 89%
0.04446
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3