Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2011-0611

CVE-2011-0611, sévérité high (CVSS 8.8) : 3 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
8.8

Échelle NVD

Exploitation
99.4 %

EPSS, prédiction à 30 jours

Apps suivies
3
Encore exposées
0

EN Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

Vecteur d'attaque : Réseau Aucun privilège requis
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 99.41% exploit probable percentile 99.9%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Adobe Acrobat Reader (64-bit) Windows winget:Adobe.Acrobat.Reader.64-bit
    Affecté ≥9.0 <9.4.4 Corrigé 9.4.4 Dernière suivie 26.002.21869 patchée
  • Chrome macOS com.google.Chrome
    Affecté <10.0.648.205 Corrigé 10.0.648.205 Dernière suivie - indéterminé
  • Google Chrome Windows winget:Google.Chrome
    Affecté <10.0.648.205 Corrigé 10.0.648.205 Dernière suivie 152.0.7977.65 patchée

NVD référence 13 produits distincts pour cette CVE : seuls ceux suivis par Scout (apps des catalogues mobile et desktop) sont listés ci-dessus. Bibliothèques, serveurs et produits hors périmètre n'apparaissent pas. Liste complète sur NVD ↗

Configurations CPE vulnérables (6)
Vendor Produit Versions
adobe acrobat_reader
Toutes plateformes (wildcard)
≥9.0 <9.4.4
adobe acrobat_reader
Toutes plateformes (wildcard)
≥10.0 ≤10.0.1
adobe acrobat_reader
Toutes plateformes (wildcard)
≥9.0 <9.4.4
adobe acrobat_reader
Toutes plateformes (wildcard)
≥10.0 <10.0.3
google chrome
Toutes plateformes (wildcard)
<10.0.648.205
google chrome
Toutes plateformes (wildcard)
<10.0.648.205
Voir sur NVD ↗ Advisory · lists.opensuse.org