CVE-2005-3591
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.4%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper memory access condition, a different vulnerability than CVE-2005-2628.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 10.45% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- macromedia/flash player
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=113140426614670&w=2
- http://secunia.com/advisories/17430/Patch, Vendor Advisory
- http://secunia.com/advisories/17437/Vendor Advisory
- http://secunia.com/advisories/17481/Vendor Advisory
- http://secunia.com/advisories/17626/Vendor Advisory
- http://secunia.com/advisories/17738/Vendor Advisory
- http://securityreason.com/securityalert/149
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.htmlVendor Advisory
- http://www.microsoft.com/technet/security/advisory/910550.mspxVendor Advisory
- http://www.sec-consult.com/226.htmlExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15334Exploit, Patch
- http://www.vupen.com/english/advisories/2005/2317Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23022
- http://marc.info/?l=bugtraq&m=113140426614670&w=2
- http://secunia.com/advisories/17430/Patch, Vendor Advisory
- http://secunia.com/advisories/17437/Vendor Advisory
- http://secunia.com/advisories/17481/Vendor Advisory
- http://secunia.com/advisories/17626/Vendor Advisory
- http://secunia.com/advisories/17738/Vendor Advisory
- http://securityreason.com/securityalert/149
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.htmlVendor Advisory
- http://www.microsoft.com/technet/security/advisory/910550.mspxVendor Advisory
- http://www.sec-consult.com/226.htmlExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15334Exploit, Patch
- http://www.vupen.com/english/advisories/2005/2317Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23022
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.