Lucene search

K
nessusTenable6802.PRM
HistoryMay 08, 2013 - 12:00 a.m.

Flash Player <= 10.3.183.16 / 11.1.102.63 Multiple Memory Corruption Vulnerabilities (APSB12-07)

2013-05-0800:00:00
Tenable
www.tenable.com
19

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.044

Percentile

92.4%

The remote host has Adobe Flash Player installed.

Versions of Flash Player 10.x equal to or earlier than 10.3.183.16 or 11.x equal to or ealier than 11.1.102.63 are potentially affected by several critical memory corruption vulnerabilities :

  • Memory corruption vulnerabilities related to URL security domain checking. (CVE-2012-0772)

  • A flaw in the NetStream Class that could lead to remote code execution. (CVE-2012-0773)

  • Two Flash Player memory corruption vulnerabilities related to the Google Chrome interface. (CVE-2012-0724, CVE-2012-0725)

By tricking a victim into visiting a specially crafted page, an attacker may be able to utilize these vulnerabilities to execute arbitrary code subject to the users’ privileges

Binary data 6802.prm
VendorProductVersionCPE
adobeflash_playercpe:/a:adobe:flash_player

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.044

Percentile

92.4%