CVE-2019-7837Use After Free in Adobe Flash Player

CWE-416Use After Free6 documents6 sources
Severity
8.8HIGHNVD
EPSS
2.3%
top 15.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22
Latest updateMay 24

Description

Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

NVDadobe/flash_player32.0.0.171
CVEListV5adobe/adobe_flash_player32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171  and earlier versions

🔴Vulnerability Details

3
GHSA
GHSA-6rxx-j8m3-g7f8: Adobe Flash Player versions 322022-05-24
CVEList
CVE-2019-7837: Adobe Flash Player versions 322019-05-22
OSV
CVE-2019-7837: Adobe Flash Player versions 322019-05-22

📋Vendor Advisories

1
Red Hat
flash-plugin: Arbitrary Code Execution vulnerability (APSB19-26)2019-05-14

💬Community

1
Bugzilla
CVE-2019-7837 flash-plugin: Arbitrary Code Execution vulnerability (APSB19-26)2019-05-14
CVE-2019-7837 — Use After Free in Adobe Flash Player | cvebase