CVE-2017-3106

Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
adobeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
redhatenterprise_linux
6.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_workstation
6.0
adobeflash_player_desktop_runtime
𝑥
≤ 26.0.0.137
adobeflash_player
𝑥
≤ 26.0.0.137
adobeflash_player
𝑥
≤ 26.0.0.137
adobeflash_player
𝑥
≤ 26.0.0.137
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
zesty
Fixed 1:20170808.1-0ubuntu0.17.04.1
released
xenial
Fixed 1:20170808.1-0ubuntu0.16.04.1
released
trusty
Fixed 1:20170808.1-0ubuntu0.14.04.1
released
flashplugin-nonfree
zesty
Fixed 26.0.0.151ubuntu0.17.04.1
released
xenial
Fixed 26.0.0.151ubuntu0.16.04.1
released
trusty
Fixed 26.0.0.151ubuntu0.14.04.1
released