CVE-2017-3071
published 2017-05-09CVE-2017-3071: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploitation could…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
6.21%
92.8th percentile
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploitation could lead to arbitrary code execution.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 25.0.0.148 | — |
| adobe | flash_player_desktop_runtime | <= 25.0.0.163 | — |
| adobe | flash_player_desktop_runtime | <= 25.0.0.148 | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: sandbox escape in indexeddb
vendor_redhat·2017-06-15·CVSS 8.8
CVE-2017-5087 [HIGH] chromium-browser: sandbox escape in indexeddb
chromium-browser: sandbox escape in indexeddb
A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, aka an IndexedDB sandbox escape.
Red Hat
chromium-browser: domain spoofing in omnibox
vendor_redhat·2017-06-15·CVSS 6.5
CVE-2017-5089 [MEDIUM] chromium-browser: domain spoofing in omnibox
chromium-browser: domain spoofing in omnibox
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.104 for Mac allowed a remote attacker to perform domain spoofing via a crafted domain name.
Red Hat
chromium-browser: out of bounds read in v8
vendor_redhat·2017-06-15·CVSS 8.8
CVE-2017-5088 [HIGH] chromium-browser: out of bounds read in v8
chromium-browser: out of bounds read in v8
Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
Red Hat
chromium-browser: ui spoofing in blink
vendor_redhat·2017-06-05·CVSS 4.3
CVE-2017-5083 [MEDIUM] chromium-browser: ui spoofing in blink
chromium-browser: ui spoofing in blink
Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
Red Hat
chromium-browser: address spoofing in omnibox
vendor_redhat·2017-06-05·CVSS 6.5
CVE-2017-5076 [MEDIUM] chromium-browser: address spoofing in omnibox
chromium-browser: address spoofing in omnibox
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Red Hat
chromium-browser: information leak in csp reporting
vendor_redhat·2017-06-05·CVSS 4.3
CVE-2017-5075 [MEDIUM] chromium-browser: information leak in csp reporting
chromium-browser: information leak in csp reporting
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.
Red Hat
chromium-browser: heap buffer overflow in skia
vendor_redhat·2017-06-05·CVSS 8.8
CVE-2017-5077 [HIGH] chromium-browser: heap buffer overflow in skia
chromium-browser: heap buffer overflow in skia
Insufficient validation of untrusted input in Skia in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: extension verification bypass
vendor_redhat·2017-06-05·CVSS 3.3
CVE-2017-5081 [LOW] chromium-browser: extension verification bypass
chromium-browser: extension verification bypass
Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.
Red Hat
chromium-browser: address spoofing in omnibox
vendor_redhat·2017-06-05·CVSS 6.5
CVE-2017-5072 [MEDIUM] chromium-browser: address spoofing in omnibox
chromium-browser: address spoofing in omnibox
Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.
Red Hat
chromium-browser: use after free in credit card autofill
vendor_redhat·2017-06-05·CVSS 8.8
CVE-2017-5080 [HIGH] chromium-browser: use after free in credit card autofill
chromium-browser: use after free in credit card autofill
A use after free in credit card autofill in Google Chrome prior to 59.0.3071.86 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: possible command injection in mailto handling
vendor_redhat·2017-06-05·CVSS 7.5
CVE-2017-5078 [HIGH] chromium-browser: possible command injection in mailto handling
chromium-browser: possible command injection in mailto handling
Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space character can be used in front of a command-line argument.
Red Hat
chromium-browser: insufficient hardening in credit card editor
vendor_redhat·2017-06-05·CVSS 5.5
CVE-2017-5082 [MEDIUM] chromium-browser: insufficient hardening in credit card editor
chromium-browser: insufficient hardening in credit card editor
Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page.
Red Hat
chromium-browser: use after free in apps bluetooth
vendor_redhat·2017-06-05·CVSS 8.0
CVE-2017-5074 [HIGH] chromium-browser: use after free in apps bluetooth
chromium-browser: use after free in apps bluetooth
A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth.
Red Hat
chromium-browser: address spoofing in omnibox
vendor_redhat·2017-06-05·CVSS 6.5
CVE-2017-5086 [MEDIUM] chromium-browser: address spoofing in omnibox
chromium-browser: address spoofing in omnibox
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Red Hat
chromium-browser: type confusion in v8
vendor_redhat·2017-06-05·CVSS 8.8
CVE-2017-5070 [HIGH] chromium-browser: type confusion in v8
chromium-browser: type confusion in v8
Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Red Hat
chromium-browser: out of bounds read in v8
vendor_redhat·2017-06-05·CVSS 6.3
CVE-2017-5071 [MEDIUM] chromium-browser: out of bounds read in v8
chromium-browser: out of bounds read in v8
Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: use after free in print preview
vendor_redhat·2017-06-05·CVSS 8.8
CVE-2017-5073 [HIGH] chromium-browser: use after free in print preview
chromium-browser: use after free in print preview
Use after free in print preview in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: ui spoofing in blink
vendor_redhat·2017-06-05·CVSS 4.3
CVE-2017-5079 [MEDIUM] chromium-browser: ui spoofing in blink
chromium-browser: ui spoofing in blink
Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB17-15
vendor_redhat·2017-05-09·CVSS 8.8
CVE-2017-3071 [HIGH] flash-plugin: multiple code execution issues fixed in APSB17-15
flash-plugin: multiple code execution issues fixed in APSB17-15
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploitation could lead to arbitrary code execution.
GHSA
GHSA-jfvx-4557-pgcj: Adobe Flash Player versions 25
ghsa_unreviewed·2022-05-13
CVE-2017-3071 [CRITICAL] CWE-416 GHSA-jfvx-4557-pgcj: Adobe Flash Player versions 25
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploitation could lead to arbitrary code execution.
OSV
CVE-2017-3071: Adobe Flash Player versions 25
osv·2017-05-09·CVSS 8.8
CVE-2017-3071 [HIGH] CVE-2017-3071: Adobe Flash Player versions 25
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploitation could lead to arbitrary code execution.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-3068 CVE-2017-3069 CVE-2017-3070 CVE-2017-3071 CVE-2017-3072 CVE-2017-3073 CVE-2017-3074 flash-plugin: multiple code execution issues fixed in APSB17-15
bugzilla·2017-05-09·CVSS 8.8
CVE-2017-3068 [HIGH] CVE-2017-3068 CVE-2017-3069 CVE-2017-3070 CVE-2017-3071 CVE-2017-3072 CVE-2017-3073 CVE-2017-3074 flash-plugin: multiple code execution issues fixed in APSB17-15
CVE-2017-3068 CVE-2017-3069 CVE-2017-3070 CVE-2017-3071 CVE-2017-3072 CVE-2017-3073 CVE-2017-3074 flash-plugin: multiple code execution issues fixed in APSB17-15
Adobe Security Bulletin APSB17-15 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-15:
These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2017-3071).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2017-3068, CVE-2017-3069, CVE-2017-3070, CVE-2017-3072, CVE-2017-3073, CVE-2017-3074).
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-15.html
Discussion:
This issue has been addres
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 05-09-2017
blogs_zscaler·CVSS 8.8
[HIGH] Zscaler discovers Flash Player Vulnerabilities | 05-09-2017
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/98347http://www.securitytracker.com/id/1038427https://access.redhat.com/errata/RHSA-2017:1219https://helpx.adobe.com/security/products/flash-player/apsb17-15.htmlhttps://security.gentoo.org/glsa/201705-12http://www.securityfocus.com/bid/98347http://www.securitytracker.com/id/1038427https://access.redhat.com/errata/RHSA-2017:1219https://helpx.adobe.com/security/products/flash-player/apsb17-15.htmlhttps://security.gentoo.org/glsa/201705-12
2017-05-09
Published