CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
99.2%
Severity: Critical
Date : 2017-02-17
CVE-ID : CVE-2017-2982 CVE-2017-2984 CVE-2017-2985 CVE-2017-2987
CVE-2017-2988 CVE-2017-2990 CVE-2017-2991 CVE-2017-2992
CVE-2017-2993 CVE-2017-2994 CVE-2017-2995 CVE-2017-2996
Package : flashplugin
Type : arbitrary code execution
Remote : Yes
Link : https://security.archlinux.org/AVG-176
The package flashplugin before version 24.0.0.221-1 is vulnerable to
arbitrary code execution.
Upgrade to 24.0.0.221-1.
The problems have been fixed upstream in version 24.0.0.221.
None.
A use-after-free vulnerability possibly leading to code execution has
been found in Adobe Flash Player < 24.0.0.221.
A heap-based buffer overflow vulnerability possibly leading to code
execution has been found in Adobe Flash Player < 24.0.0.221.
A use-after-free vulnerability possibly leading to code execution has
been found in Adobe Flash Player < 24.0.0.221.
An integer overflow vulnerability possibly leading to code execution
has been found in Adobe Flash Player < 24.0.0.221.
A memory corruption vulnerability possibly leading to code execution
has been found in Adobe Flash Player < 24.0.0.221.
A memory corruption vulnerability possibly leading to code execution
has been found in Adobe Flash Player < 24.0.0.221.
A memory corruption vulnerability possibly leading to code execution
has been found in Adobe Flash Player < 24.0.0.221.
A heap-based buffer overflow vulnerability possibly leading to code
execution has been found in Adobe Flash Player < 24.0.0.221.
A use-after-free vulnerability possibly leading to code execution has
been found in Adobe Flash Player < 24.0.0.221.
A use-after-free vulnerability possibly leading to code execution has
been found in Adobe Flash Player < 24.0.0.221.
A type confusion vulnerability possibly leading to code execution has
been found in Adobe Flash Player < 24.0.0.221.
A memory corruption vulnerability possibly leading to code execution
has been found in Adobe Flash Player < 24.0.0.221.
A remote attacker can execute arbitrary code on the affected host.
https://helpx.adobe.com/security/products/flash-player/apsb17-04.html
https://security.archlinux.org/CVE-2017-2982
https://security.archlinux.org/CVE-2017-2984
https://security.archlinux.org/CVE-2017-2985
https://security.archlinux.org/CVE-2017-2987
https://security.archlinux.org/CVE-2017-2988
https://security.archlinux.org/CVE-2017-2990
https://security.archlinux.org/CVE-2017-2991
https://security.archlinux.org/CVE-2017-2992
https://security.archlinux.org/CVE-2017-2993
https://security.archlinux.org/CVE-2017-2994
https://security.archlinux.org/CVE-2017-2995
https://security.archlinux.org/CVE-2017-2996
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ArchLinux | any | any | flashplugin | < 24.0.0.221-1 | UNKNOWN |
helpx.adobe.com/security/products/flash-player/apsb17-04.html
security.archlinux.org/AVG-176
security.archlinux.org/CVE-2017-2982
security.archlinux.org/CVE-2017-2984
security.archlinux.org/CVE-2017-2985
security.archlinux.org/CVE-2017-2987
security.archlinux.org/CVE-2017-2988
security.archlinux.org/CVE-2017-2990
security.archlinux.org/CVE-2017-2991
security.archlinux.org/CVE-2017-2992
security.archlinux.org/CVE-2017-2993
security.archlinux.org/CVE-2017-2994
security.archlinux.org/CVE-2017-2995
security.archlinux.org/CVE-2017-2996
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
99.2%