peter bassill · operator
$ cve CVE-2017-3114 JSON

CVE-2017-3114

9.8
CRITICAL · CVSS 3.0 · EPSS 6.2% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.22% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-125
On CISA KEVno
Public exploitnone known
Published2017-12-09
Last modified2026-06-17

Affected (10)

VendorProduct
adobeflash player
applemacos
googlechrome os
linuxlinux kernel
microsoftwindows
microsoftwindows 10
microsoftwindows 8.1
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD