CVE-2017-2987
published 2017-02-15CVE-2017-2987: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerability related to Flash Broker COM. Successful exploitation…
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
8.53%
94.4th percentile
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerability related to Flash Broker COM. Successful exploitation could lead to arbitrary code execution.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 24.0.0.194 | — |
| adobe | flash_player_desktop_runtime | <= 24.0.0.194 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: bad cast in blink
vendor_redhat·2017-03-29·CVSS 8.8
CVE-2017-5052 [HIGH] chromium-browser: bad cast in blink
chromium-browser: bad cast in blink
An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page that triggers improper casting.
Red Hat
chromium-browser: heap buffer overflow in v8
vendor_redhat·2017-03-29·CVSS 8.8
CVE-2017-5054 [HIGH] chromium-browser: heap buffer overflow in v8
chromium-browser: heap buffer overflow in v8
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to obtain heap memory contents via a crafted HTML page.
Red Hat
chromium-browser: out of bounds memory access in v8
vendor_redhat·2017-03-29·CVSS 9.6
CVE-2017-5053 [CRITICAL] chromium-browser: out of bounds memory access in v8
chromium-browser: out of bounds memory access in v8
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.
Red Hat
chromium-browser: use after free in blink
vendor_redhat·2017-03-29·CVSS 8.8
CVE-2017-5056 [HIGH] chromium-browser: use after free in blink
chromium-browser: use after free in blink
A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: use after free in printing
vendor_redhat·2017-03-29·CVSS 8.8
CVE-2017-5055 [HIGH] chromium-browser: use after free in printing
chromium-browser: use after free in printing
A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: out of bounds write in pdfium
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5032 [HIGH] chromium-browser: out of bounds write in pdfium
chromium-browser: out of bounds write in pdfium
PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Red Hat
chromium-browser: multiple out of bounds writes in chunkdemuxer
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5048 [HIGH] chromium-browser: multiple out of bounds writes in chunkdemuxer
chromium-browser: multiple out of bounds writes in chunkdemuxer
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Affected
Red Hat
chromium-browser: address spoofing in omnibox
vendor_redhat·2017-03-09·CVSS 4.3
CVE-2017-5041 [MEDIUM] chromium-browser: address spoofing in omnibox
chromium-browser: address spoofing in omnibox
Google Chrome prior to 57.0.2987.100 incorrectly handled back-forward navigation, which allowed a remote attacker to display incorrect information for a site via a crafted HTML page.
Red Hat
chromium-browser: use after free in pdfium
vendor_redhat·2017-03-09·CVSS 7.8
CVE-2017-5036 [HIGH] chromium-browser: use after free in pdfium
chromium-browser: use after free in pdfium
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF file.
Red Hat
chromium-browser: information disclosure in v8
vendor_redhat·2017-03-09·CVSS 4.3
CVE-2017-5040 [MEDIUM] chromium-browser: information disclosure in v8
chromium-browser: information disclosure in v8
V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.
Red Hat
chromium-browser: information disclosure in xss auditor
vendor_redhat·2017-03-09·CVSS 6.1
CVE-2017-5045 [MEDIUM] chromium-browser: information disclosure in xss auditor
chromium-browser: information disclosure in xss auditor
XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page.
Red Hat
chromium-browser: multiple out of bounds writes in chunkdemuxer
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5049 [HIGH] chromium-browser: multiple out of bounds writes in chunkdemuxer
chromium-browser: multiple out of bounds writes in chunkdemuxer
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Affected
Red Hat
chromium-browser: use after free in guestview
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5043 [HIGH] chromium-browser: use after free in guestview
chromium-browser: use after free in guestview
Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.
Red Hat
chromium-browser: use after free in pdfium
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5034 [HIGH] chromium-browser: use after free in pdfium
chromium-browser: use after free in pdfium
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
Red Hat
chromium-browser: bypass of content security policy in blink
vendor_redhat·2017-03-09·CVSS 4.3
CVE-2017-5033 [MEDIUM] chromium-browser: bypass of content security policy in blink
chromium-browser: bypass of content security policy in blink
Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page, related to the unsafe-inline keyword.
Red Hat
chromium-browser: memory corruption in v8
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5030 [HIGH] chromium-browser: memory corruption in v8
chromium-browser: memory corruption in v8
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.
Red Hat
chromium-browser: integer overflow in libxslt
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5029 [HIGH] chromium-browser: integer overflow in libxslt
chromium-browser: integer overflow in libxslt
The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
Red Hat
chromium-browser: use after free in angle
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5031 [HIGH] chromium-browser: use after free in angle
chromium-browser: use after free in angle
A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: multiple out of bounds writes in chunkdemuxer
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5047 [HIGH] chromium-browser: multiple out of bounds writes in chunkdemuxer
chromium-browser: multiple out of bounds writes in chunkdemuxer
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Affected
Red Hat
chromium-browser: heap overflow in skia
vendor_redhat·2017-03-09·CVSS 6.3
CVE-2017-5044 [MEDIUM] chromium-browser: heap overflow in skia
chromium-browser: heap overflow in skia
Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: incorrect handling of cookies in cast
vendor_redhat·2017-03-09·CVSS 5.7
CVE-2017-5042 [MEDIUM] chromium-browser: incorrect handling of cookies in cast
chromium-browser: incorrect handling of cookies in cast
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
Red Hat
chromium-browser: use after free in pdfium
vendor_redhat·2017-03-09·CVSS 7.8
CVE-2017-5039 [HIGH] chromium-browser: use after free in pdfium
chromium-browser: use after free in pdfium
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Red Hat
chromium-browser: incorrect security ui in omnibox
vendor_redhat·2017-03-09·CVSS 8.1
CVE-2017-5035 [HIGH] chromium-browser: incorrect security ui in omnibox
chromium-browser: incorrect security ui in omnibox
Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site.
Red Hat
chromium-browser: multiple out of bounds writes in chunkdemuxer
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5050 [HIGH] chromium-browser: multiple out of bounds writes in chunkdemuxer
chromium-browser: multiple out of bounds writes in chunkdemuxer
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Affected
Red Hat
chromium-browser: information disclosure in blink
vendor_redhat·2017-03-09·CVSS 4.3
CVE-2017-5046 [MEDIUM] chromium-browser: information disclosure in blink
chromium-browser: information disclosure in blink
V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android had insufficient policy enforcement, which allowed a remote attacker to spoof the location object via a crafted HTML page, related to Blink information disclosure.
Red Hat
chromium-browser: multiple out of bounds writes in chunkdemuxer
vendor_redhat·2017-03-09·CVSS 7.8
CVE-2017-5037 [HIGH] chromium-browser: multiple out of bounds writes in chunkdemuxer
chromium-browser: multiple out of bounds writes in chunkdemuxer
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Red Hat
chromium-browser: use after free in guestview
vendor_redhat·2017-03-09·CVSS 6.3
CVE-2017-5038 [MEDIUM] chromium-browser: use after free in guestview
chromium-browser: use after free in guestview
Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.
Red Hat
chromium-browser: multiple out of bounds writes in chunkdemuxer
vendor_redhat·2017-03-09·CVSS 8.8
CVE-2017-5051 [HIGH] chromium-browser: multiple out of bounds writes in chunkdemuxer
chromium-browser: multiple out of bounds writes in chunkdemuxer
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Affected
Red Hat
flash-plugin: multiple code execution issues fixed in APSB17-04
vendor_redhat·2017-02-14·CVSS 8.8
CVE-2017-2987 [HIGH] flash-plugin: multiple code execution issues fixed in APSB17-04
flash-plugin: multiple code execution issues fixed in APSB17-04
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerability related to Flash Broker COM. Successful exploitation could lead to arbitrary code execution.
Package: flash-plugin (Red Hat Enterprise Linux 5) - Will not fix
GHSA
GHSA-cqr9-g2qv-xv6v: Adobe Flash Player versions 24
ghsa_unreviewed·2022-05-14
CVE-2017-2987 [CRITICAL] CWE-190 GHSA-cqr9-g2qv-xv6v: Adobe Flash Player versions 24
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerability related to Flash Broker COM. Successful exploitation could lead to arbitrary code execution.
OSV
CVE-2017-2987: Adobe Flash Player versions 24
osv·2017-02-15·CVSS 8.8
CVE-2017-2987 [HIGH] CVE-2017-2987: Adobe Flash Player versions 24
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerability related to Flash Broker COM. Successful exploitation could lead to arbitrary code execution.
No detection rules found.
Bugzilla
Address bar spoof in reader mode
bugzilla·2017-04-20·CVSS 5.3
[MEDIUM] Address bar spoof in reader mode
Address bar spoof in reader mode
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36
Steps to reproduce:
1. Go to about:reader?url=https%3A%2F%2Ftest.shhnjk.com%2Fcsp_read.php
Actual results:
address before @ is shown in address bar which could be used for phishing.
Expected results:
user information (left side of @) in url should not be shown in address bar. This is incomplete fix of https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5463
Discussion:
Sorry,
This is incomplete fix of https://bugzilla.mozilla.org/show_bug.cgi?id=1338867
---
Was this report intended to be about Firefox for Desktop or for Android?
---
Desktop.
---
Created attachment 8860639
Patch to fix url
Bugzilla
CVE-2017-2982 CVE-2017-2984 CVE-2017-2985 CVE-2017-2986 CVE-2017-2987 CVE-2017-2988 CVE-2017-2990 CVE-2017-2991 CVE-2017-2992 CVE-2017-2993 CVE-2017-2995 CVE-2017-2996 flash-plugin: multiple code exec
bugzilla·2017-02-14·CVSS 8.8
CVE-2017-2982 [HIGH] CVE-2017-2982 CVE-2017-2984 CVE-2017-2985 CVE-2017-2986 CVE-2017-2987 CVE-2017-2988 CVE-2017-2990 CVE-2017-2991 CVE-2017-2992 CVE-2017-2993 CVE-2017-2995 CVE-2017-2996 flash-plugin: multiple code exec
CVE-2017-2982 CVE-2017-2984 CVE-2017-2985 CVE-2017-2986 CVE-2017-2987 CVE-2017-2988 CVE-2017-2990 CVE-2017-2991 CVE-2017-2992 CVE-2017-2993 CVE-2017-2995 CVE-2017-2996 flash-plugin: multiple code execution issues fixed in APSB17-04
Adobe Security Bulletin APSB17-04 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-04:
These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2017-2995).
These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2017-2987).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2017-2982, CVE-2017-2985, CVE-2017-2993, CVE-
Zscaler
Zscaler protects against 12 new vulnerabilities for Adobe Flash Player. | Zscaler
blogs_zscaler
Zscaler protects against 12 new vulnerabilities for Adobe Flash Player. | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://rhn.redhat.com/errata/RHSA-2017-0275.htmlhttp://www.securityfocus.com/bid/96194http://www.securitytracker.com/id/1037815https://helpx.adobe.com/security/products/flash-player/apsb17-04.htmlhttps://security.gentoo.org/glsa/201702-20http://rhn.redhat.com/errata/RHSA-2017-0275.htmlhttp://www.securityfocus.com/bid/96194http://www.securitytracker.com/id/1037815https://helpx.adobe.com/security/products/flash-player/apsb17-04.htmlhttps://security.gentoo.org/glsa/201702-20
2017-02-15
Published