These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2017-2995 is a high-severity Adobe Flash Player vulnerability first published on 2017-02-15. NVD describes it as a type confusion issue in the MessageChannel class that could allow arbitrary code execution in Flash Player versions 24.0.0.194 and earlier. The NVD record assigns a CVSS 3.1 score of 8.8 (HIGH), reflecting network attackability, low attack complexity, no privileges required, and user inte [truncated]
CVE-2017-2994 is a high-severity Adobe Flash Player vulnerability involving a use-after-free in Primetime SDK event dispatch. The issue was publicly disclosed on 2017-02-15 and, if successfully triggered, could allow arbitrary code execution. The supplied corpus shows the vulnerability affecting multiple Flash Player variants and browser-integrated deployments, with a user interaction requirement in the CVSS vector.
CVE-2017-2993 is a high-severity Adobe Flash Player memory-safety issue. In the supplied record, versions 24.0.0.194 and earlier are affected, and successful exploitation could lead to arbitrary code execution. The vulnerability is classified as CWE-416 (use after free) and the NVD vector shows network-based attack conditions with user interaction required.
CVE-2017-2992 is a high-severity Adobe Flash Player memory corruption issue. According to NVD and Adobe-linked references, parsing an MP4 header can trigger a heap overflow in affected Flash Player versions 24.0.0.194 and earlier, and successful exploitation could lead to arbitrary code execution.
CVE-2017-2991 is a high-severity Adobe Flash Player memory corruption issue affecting versions 24.0.0.194 and earlier. According to the NVD record and Adobe-linked advisory references, the flaw is in the h264 codec decompression path and could be exploited for arbitrary code execution when a user interacts with malicious content.
CVE-2017-2990 is a high-severity Adobe Flash Player memory corruption issue in the H.264 decompression routine. NVD maps it to CWE-787 and a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating network-based exploitation that requires user interaction and can have major confidentiality, integrity, and availability impact. The supplied CPE data marks Flash Player in Chrome, Edge, Internet Exp [truncated]
CVE-2017-2988 is an Adobe Flash Player memory corruption vulnerability tied to garbage collection. According to the NVD record, it affects Flash Player versions 24.0.0.194 and earlier in the listed Chrome, Edge, Internet Explorer, and desktop runtime deployment contexts. Successful exploitation could lead to arbitrary code execution. The CVE was published on 2017-02-15, and the NVD record was later modifi [truncated]
CVE-2017-2987 is a high-severity Adobe Flash Player vulnerability involving an integer overflow in Flash Broker COM. NVD rates the issue CVSS 8.8 and states that successful exploitation could lead to arbitrary code execution. The affected scope in NVD includes Flash Player 24.0.0.194 and earlier, across browser-integrated and desktop runtime variants.
CVE-2017-2986 is a high-severity Adobe Flash Player memory corruption issue in the Flash Video (FLV) codec. NVD describes it as an exploitable heap overflow that could lead to arbitrary code execution, with a CVSS 3.1 score of 8.8 and attack vector/network plus user interaction required. Adobe’s advisory APSB17-04 and the NVD record indicate affected Flash Player builds at or below 24.0.0.194 across brows [truncated]
CVE-2017-2985 is a high-severity Adobe Flash Player flaw in the ActionScript 3 BitmapData class. Adobe’s advisory and the NVD record describe it as a use-after-free (CWE-416) that can be exploited to achieve arbitrary code execution. The NVD record maps the issue to Flash Player versions 24.0.0.194 and earlier across the listed browser/runtime CPEs.
CVE-2017-2984 is a high-severity Adobe Flash Player vulnerability published on 2017-02-15. The issue is an exploitable heap overflow in the H.264 decoder routine, and successful exploitation could lead to arbitrary code execution. NVD maps the issue to CWE-787 and rates it CVSS 3.1 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Adobe’s advisory APSB17-04 is the primary patch reference in the supplied corpus.
CVE-2017-2982 is a high-severity Adobe Flash Player use-after-free vulnerability in a routine related to player shutdown. Adobe and NVD identify affected Flash Player builds as versions 24.0.0.194 and earlier, and the issue can lead to arbitrary code execution if successfully exploited. The NVD CVSS 3.1 vector shows network attack conditions with user interaction required.
CVE-2017-2981 affects Adobe Digital Editions 4.5.3 and earlier. According to the NVD record, the issue is an exploitable buffer over-read that can lead to information disclosure. Adobe’s advisory is referenced in the source corpus, and the NVD entry classifies the weakness as CWE-125 with a HIGH severity score.
CVE-2017-2980 is a high-severity Adobe Digital Editions issue affecting version 4.5.3 and earlier. According to the NVD record, the flaw is a buffer over-read (CWE-125) and successful exploitation could result in information disclosure. The public record points to Adobe’s APSB17-05 advisory and the NVD entry for affected-version and remediation context.
CVE-2017-2979 affects Adobe Digital Editions 4.5.3 and earlier. Public records describe an exploitable buffer over-read that can lead to information disclosure. NVD classifies the issue as CWE-125 and assigns a CVSS 3.0 score of 7.5 HIGH.
CVE-2017-2978 affects Adobe Digital Editions versions 4.5.3 and earlier. The issue is described as an exploitable buffer over-read that can lead to information disclosure, and NVD classifies it as CWE-125 with a HIGH CVSS 3.0 score of 7.5. Systems that still use affected versions should be updated using Adobe’s security guidance.
CVE-2017-2977 affects Adobe Digital Editions 4.5.3 and earlier. Public sources describe an exploitable buffer over-read that can lead to information disclosure, and NVD rates the issue HIGH with a 7.5 CVSS score. Organizations that use Adobe Digital Editions to open untrusted content should treat this as a priority exposure and verify they are running a fixed version.
CVE-2017-2976 affects Adobe Digital Editions 4.5.3 and earlier. NVD describes the flaw as an exploitable buffer over-read (CWE-125) with potential for information disclosure. The record is rated HIGH and the supplied NVD vector shows network-exploitable conditions with no privileges required.
CVE-2017-2975 is a publicly disclosed vulnerability in Adobe Digital Editions 4.5.3 and earlier. NVD describes it as an exploitable buffer over-read issue, and Adobe’s advisory is the primary vendor reference. The issue is associated with CWE-125 and carries a CVSS v3.0 score of 7.5 (High).
CVE-2017-2974 affects Adobe Digital Editions versions 4.5.3 and earlier. The official CVE description says successful exploitation could lead to information disclosure, while the NVD record classifies the flaw as CWE-125 and gives it a 7.5 High CVSS score. From a defensive standpoint, this is a serious issue for any environment that still runs affected Adobe Digital Editions builds, especially because the [truncated]
CVE-2017-2973 is a critical Adobe Digital Editions vulnerability disclosed on 2017-02-15. Adobe and NVD describe an exploitable heap overflow affecting versions 4.5.3 and earlier, with successful exploitation potentially leading to arbitrary code execution.
CVE-2017-2969 is a cross-site scripting (XSS) vulnerability in Adobe Campaign versions 16.4 Build 8724 and earlier. The NVD record rates it CVSS 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N), which means it is reachable over the network, requires user interaction, and can affect the victim's browser session.
CVE-2017-2968 is a critical Adobe Campaign code injection vulnerability affecting versions 16.4 Build 8724 and earlier. NVD rates the issue CVSS 3.0 9.1, indicating network-based exploitation with low attack complexity and no privileges or user interaction, with high potential impact to confidentiality and integrity.
CVE-2017-2972 is a high-severity memory corruption issue in Adobe Acrobat Reader and related Acrobat DC releases. Adobe and NVD describe it as an exploitable flaw in the image conversion module, specifically related to JPEG parsing, with successful exploitation potentially leading to arbitrary code execution.
CVE-2017-2971 is a high-severity Adobe Acrobat Reader/Acrobat memory-corruption issue in the JPEG decoder routine. The flaw can allow arbitrary code execution in affected versions when a user opens content that reaches the vulnerable parser. NVD classifies the issue as requiring user interaction and lists affected Adobe Reader/Acrobat builds up to the versions in the advisory and CPE ranges.
CVE-2017-2970 is a heap overflow vulnerability in Adobe Acrobat Reader/Acrobat's XSLT engine related to template manipulation. According to the NVD record, successful exploitation could lead to arbitrary code execution. The issue affects the specific Adobe version ranges listed in the advisory and is rated High severity.
CVE-2017-2929 is a medium-severity DOM-based cross-site scripting issue in the Adobe Acrobat Chrome extension version 15.1.0.3 and earlier. According to NVD, successful exploitation could lead to JavaScript code execution. Adobe’s security advisory APSB17-03 is listed as the patch reference.