CVE-2017-3085
published 2017-08-11CVE-2017-3085: Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
PriorityP336high7.4CVSS 3.1
AVNACLPRNUIRSCCHINAN
EPSS
4.48%
90.5th percentile
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 26.0.0.137 | — |
| adobe | flash_player_desktop_runtime | <= 26.0.0.137 | — |
| adobe_systems_incorporated | flash_player | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: Information Disclosure via Security Bypass issue fixed in APSB17-23
vendor_redhat·2017-08-08·CVSS 7.4
CVE-2017-3085 [HIGH] CWE-200 flash-plugin: Information Disclosure via Security Bypass issue fixed in APSB17-23
flash-plugin: Information Disclosure via Security Bypass issue fixed in APSB17-23
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
GHSA
GHSA-p58g-v8g4-qrc3: Adobe Flash Player versions 26
ghsa_unreviewed·2022-05-13
CVE-2017-3085 [HIGH] CWE-200 GHSA-p58g-v8g4-qrc3: Adobe Flash Player versions 26
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
OSV
CVE-2017-3085: Adobe Flash Player versions 26
osv·2017-08-11·CVSS 7.4
CVE-2017-3085 [HIGH] CVE-2017-3085: Adobe Flash Player versions 26
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/100191http://www.securitytracker.com/id/1039088http://www.zerodayinitiative.com/advisories/ZDI-17-634/https://access.redhat.com/errata/RHSA-2017:2457https://blog.bjornweb.nl/2017/08/flash-remote-sandbox-escape-windows-user-credentials-leak/https://helpx.adobe.com/security/products/flash-player/apsb17-23.htmlhttps://security.gentoo.org/glsa/201709-16http://www.securityfocus.com/bid/100191http://www.securitytracker.com/id/1039088http://www.zerodayinitiative.com/advisories/ZDI-17-634/https://access.redhat.com/errata/RHSA-2017:2457https://blog.bjornweb.nl/2017/08/flash-remote-sandbox-escape-windows-user-credentials-leak/https://helpx.adobe.com/security/products/flash-player/apsb17-23.htmlhttps://security.gentoo.org/glsa/201709-16
2017-08-11
Published