|
251501
|
8.8 |
HIGH
Network
|
adobe redhat
|
flash_player_desktop_runtime flash_player enterprise_linux enterprise_linux_desktop enterprise_linux_workstation
|
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multiple mask properties of display objects, aka memory corruption. Successful exploi…
|
CWE-416
Use After Free
|
CVE-2017-3073
|
2024-11-21 12:24 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251502
|
8.8 |
HIGH
Network
|
adobe redhat
|
flash_player_desktop_runtime flash_player enterprise_linux enterprise_linux_desktop enterprise_linux_workstation
|
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BitmapData class. Successful exploitation could lead to arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-3072
|
2024-11-21 12:24 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251503
|
8.8 |
HIGH
Network
|
adobe redhat
|
flash_player_desktop_runtime flash_player enterprise_linux enterprise_linux_desktop enterprise_linux_workstation
|
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploitation could lead to arbitrary code execution.
|
CWE-416
Use After Free
|
CVE-2017-3071
|
2024-11-21 12:24 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251504
|
8.8 |
HIGH
Network
|
adobe redhat
|
flash_player_desktop_runtime flash_player enterprise_linux enterprise_linux_desktop enterprise_linux_workstation
|
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the ConvolutionFilter class. Successful exploitation could lead to arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-3070
|
2024-11-21 12:24 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251505
|
8.8 |
HIGH
Network
|
adobe redhat
|
flash_player_desktop_runtime flash_player enterprise_linux enterprise_linux_desktop enterprise_linux_workstation
|
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BlendMode class. Successful exploitation could lead to arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-3069
|
2024-11-21 12:24 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251506
|
8.8 |
HIGH
Network
|
adobe redhat
|
flash_player_desktop_runtime flash_player enterprise_linux enterprise_linux_desktop enterprise_linux_workstation
|
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successful exploitation could lead to arbitrary code execut…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-3068
|
2024-11-21 12:24 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251507
|
7.5 |
HIGH
Network
|
adobe
|
experience_manager_forms
|
Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms.
|
CWE-200
Information Exposure
|
CVE-2017-3067
|
2024-11-21 12:24 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251508
|
6.1 |
MEDIUM
Network
|
adobe
|
coldfusion
|
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2017-3008
|
2024-11-21 12:24 |
2017-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251509
|
7.3 |
HIGH
Network
|
apache
|
hadoop
|
HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0.
|
CWE-20
Improper Input Validation
|
CVE-2017-3162
|
2024-11-21 12:24 |
2017-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251510
|
6.1 |
MEDIUM
Network
|
apache
|
hadoop
|
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-3161
|
2024-11-21 12:24 |
2017-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|