Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2018-4871 | First vendor Publication | 2018-01-09 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | |||
---|---|---|---|
Overall CVSS Score | 7.5 | ||
Base Score | 7.5 | Environmental Score | 7.5 |
impact SubScore | 3.6 | Temporal Score | 7.5 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | None | Availability Impact | None |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4871 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-125 | Out-of-bounds Read |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 1 | |
Os | 1 |
Snort® IPS/IDS
Date | Description |
---|---|
2018-02-14 | Adobe Flash Player malformed ATF buffer overflow attempt RuleID : 45405 - Revision : 2 - Type : FILE-FLASH |
2018-02-14 | Adobe Flash Player malformed ATF buffer overflow attempt RuleID : 45404 - Revision : 2 - Type : FILE-FLASH |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-03-19 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201803-08.nasl - Type : ACT_GATHER_INFO |
2018-01-10 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_9c016563f58211e7b33c6451062f0f7a.nasl - Type : ACT_GATHER_INFO |
2018-01-09 | Name : The remote Windows host has a browser plugin installed that is affected by an... File : flash_player_apsb18-01.nasl - Type : ACT_GATHER_INFO |
2018-01-09 | Name : The remote macOS or Mac OSX host has a browser plugin installed that is affec... File : macosx_flash_player_apsb18-01.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 13:18:48 |
|
2021-09-08 21:24:15 |
|
2021-05-04 13:15:22 |
|
2021-04-22 02:30:22 |
|
2020-05-23 01:14:18 |
|
2018-10-30 12:11:39 |
|
2018-03-02 01:04:05 |
|
2018-01-30 21:20:33 |
|
2018-01-12 09:22:44 |
|
2018-01-10 13:23:48 |
|