CVE-2006-3587
published 2006-07-13CVE-2006-3587: Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that…
PriorityP335medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
8.20%
94.2th percentile
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2006-09-12·CVSS 5.1
CVE-2006-3588 [MEDIUM] security flaw
security flaw
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to cause a denial of service (browser crash) via a malformed, compressed .swf file, a different issue than CVE-2006-3587.
Statement: Adobe gave a statement that these issues do not affect the Linux versions of Macromedia Flash Player.
Red Hat
security flaw
vendor_redhat·2006-09-12·CVSS 5.1
CVE-2006-3587 [MEDIUM] security flaw
security flaw
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.
Statement: Adobe gave a statement that these issues do not affect the Linux versions of Macromedia Flash Player.
GHSA
GHSA-hgcm-72vv-9325: Unspecified vulnerability in Adobe (Macromedia) Flash Player 8
ghsa_unreviewed·2022-05-01·CVSS 5.1
CVE-2006-3588 [MEDIUM] GHSA-hgcm-72vv-9325: Unspecified vulnerability in Adobe (Macromedia) Flash Player 8
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to cause a denial of service (browser crash) via a malformed, compressed .swf file, a different issue than CVE-2006-3587.
GHSA
GHSA-hc97-wcwr-272v: Unspecified vulnerability in Adobe (Macromedia) Flash Player 8
ghsa_unreviewed·2022-05-01
CVE-2006-3587 [MEDIUM] GHSA-hc97-wcwr-272v: Unspecified vulnerability in Adobe (Macromedia) Flash Player 8
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-3587 security flaw
bugzilla·2018-08-16·CVSS 5.1
CVE-2006-3587 [MEDIUM] CVE-2006-3587 security flaw
CVE-2006-3587 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.
---
Statement:
Adobe gave a statement that these issues do not affect the Linux versions of Macromedia Flash Player.
Bugzilla
CVE-2006-3588 security flaw
bugzilla·2018-08-16·CVSS 5.1
CVE-2006-3588 [MEDIUM] CVE-2006-3588 security flaw
CVE-2006-3588 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to cause a denial of service (browser crash) via a malformed, compressed .swf file, a different issue than CVE-2006-3587.
---
Statement:
Adobe gave a statement that these issues do not affect the Linux versions of Macromedia Flash Player.
Bugzilla
CVE-2006-3311 Multiple flash-plug flaws (CVE-2006-3587 CVE-2006-3588)
bugzilla·2006-09-11·CVSS 5.1
CVE-2006-3311 [MEDIUM] CVE-2006-3311 Multiple flash-plug flaws (CVE-2006-3587 CVE-2006-3588)
CVE-2006-3311 Multiple flash-plug flaws (CVE-2006-3587 CVE-2006-3588)
Abode notified us that a new Flash 7 player will be released on September 12th
to fix critical security flaws.
Multiple input validation errors have been identified in Flash
Player 8.0.24.0 and earlier versions that could lead to the
potential execution of arbitrary code. These vulnerabilities
could be accessed through content delivered from a remote
location via the user’s web browser, email client, or other
applications that include or reference the Flash
Player. (CVE-2006-3311, CVE-2006-3587, CVE-2006-3588)
CVE-2006-3014 is also mentioned in their advisory but only affects the Windows
platform.
Probably Affects: RHEL3 Extras
Probably Affects: RHEL4 Extras
Discussion:
removing embargo, this is now public at
http:
http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.htmlhttp://secunia.com/advisories/20971http://secunia.com/advisories/21865http://secunia.com/advisories/21901http://secunia.com/advisories/22054http://secunia.com/advisories/22187http://secunia.com/advisories/22268http://secunia.com/advisories/22882http://security.gentoo.org/glsa/glsa-200610-02.xmlhttp://securitytracker.com/id?1016448http://securitytracker.com/id?1016829http://www.adobe.com/support/security/bulletins/apsb06-11.htmlhttp://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-20.htmlhttp://www.kb.cert.org/vuls/id/474593http://www.novell.com/linux/security/advisories/2006_53_flashplayer.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0674.htmlhttp://www.securityfocus.com/bid/18894http://www.securityfocus.com/bid/19980http://www.us-cert.gov/cas/techalerts/TA06-318A.htmlhttp://www.vupen.com/english/advisories/2006/2702http://www.vupen.com/english/advisories/2006/3573http://www.vupen.com/english/advisories/2006/3577http://www.vupen.com/english/advisories/2006/3852http://www.vupen.com/english/advisories/2006/4507https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-069https://exchange.xforce.ibmcloud.com/vulnerabilities/27601https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1050https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A709http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.htmlhttp://secunia.com/advisories/20971http://secunia.com/advisories/21865http://secunia.com/advisories/21901http://secunia.com/advisories/22054http://secunia.com/advisories/22187http://secunia.com/advisories/22268http://secunia.com/advisories/22882http://security.gentoo.org/glsa/glsa-200610-02.xmlhttp://securitytracker.com/id?1016448http://securitytracker.com/id?1016829http://www.adobe.com/support/security/bulletins/apsb06-11.htmlhttp://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-20.htmlhttp://www.kb.cert.org/vuls/id/474593http://www.novell.com/linux/security/advisories/2006_53_flashplayer.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0674.htmlhttp://www.securityfocus.com/bid/18894http://www.securityfocus.com/bid/19980http://www.us-cert.gov/cas/techalerts/TA06-318A.htmlhttp://www.vupen.com/english/advisories/2006/2702http://www.vupen.com/english/advisories/2006/3573http://www.vupen.com/english/advisories/2006/3577http://www.vupen.com/english/advisories/2006/3852http://www.vupen.com/english/advisories/2006/4507https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-069https://exchange.xforce.ibmcloud.com/vulnerabilities/27601https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1050https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A709
2006-07-13
Published