Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL.
2020-10-14T14:15:17.610
2024-11-21T05:41:12.423
Modified
CVSSv3.1: 7.0 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | flash_player | ≤ 32.0.0.433 | Yes |
Operating System | apple | macos | - | No |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |
Application | adobe | flash_player | < 32.0.0.433 | Yes |
Operating System | apple | macos | - | No |
Operating System | chrome_os | - | No | |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |
Application | adobe | flash_player | < 32.0.0.387 | Yes |
Application | adobe | flash_player | < 32.0.0.387 | Yes |
Operating System | microsoft | windows_10 | - | No |
Operating System | microsoft | windows_8.1 | - | No |