Vulnerability Name: | CVE-2017-3106 (CCN-129777) | ||||||||||||||||
Assigned: | 2016-12-02 | ||||||||||||||||
Published: | 2017-08-08 | ||||||||||||||||
Updated: | 2022-11-16 | ||||||||||||||||
Summary: | Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution. | ||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
7.9 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-704 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-3106 Source: BID Type: Third Party Advisory, VDB Entry 100190 Source: CCN Type: BID-100190 Adobe Flash Player CVE-2017-3106 Type Confusion Remote Code Execution Vulnerability Source: SECTRACK Type: Broken Link, Third Party Advisory, VDB Entry 1039088 Source: REDHAT Type: Third Party Advisory RHSA-2017:2457 Source: XF Type: UNKNOWN adobe-flash-cve20173106-code-exec(129777) Source: CCN Type: Adobe Security Bulletin APSB17-23 Security updates available for Adobe Flash Player Source: CONFIRM Type: Patch, Vendor Advisory https://helpx.adobe.com/security/products/flash-player/apsb17-23.html Source: CCN Type: Packet Storm Security [08-17-2017] Adobe Flash Invoke Accesses Trait Out-Of-Bounds Source: GENTOO Type: Third Party Advisory GLSA-201709-16 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [08-17-2017] Source: EXPLOIT-DB Type: Exploit, Third Party Advisory, VDB Entry 42480 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |