CVE detail
CVE-2020-9746
Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- 19th October – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 19th October 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Researchers and telecom companies have partnered to execute a coordinated attack aimed at disrupting the infamous Trickbot botnet and Malware-as-a-Service. A Court order granted the researchers control over the botnet’s infrastructure. […]
vendorresearch.checkpoint.comOct 19, 2020, 10:05 AM - Adobe fixes Magento flaws that can lead to code executionSecurity Affairs
Adobe released a series of out-of-band security fixes to address multiple Magento vulnerabilities that lead to code execution, customer list tampering. Adobe has released a series of out-of-band security fixes to address multiple Magento vulnerabilities that lead to code execution, customer list tampering. Eight of the vulnerabilities are considered either critical or important, only one […]
newssecurityaffairs.comOct 16, 2020, 12:42 PM - October 2020 Patch Tuesday: Microsoft fixes potentially wormable Windows TCP/IP RCE flawHelp Net Security
On this October 2020 Patch Tuesday: Microsoft has plugged 87 security holes, including critical ones in the Windows TCP/IP stack and Microsoft Outlook and Microsoft 365 Apps for Enterprise Adobe has delivered security updates for Adobe Flash Player Intel warns about flaws in BlueZ, the official Linux Bluetooth protocol stack SAP has released 15 security notes and updates to 6 previously released ones. Microsoft’s updates Microsoft has released patches for 87 CVE-numbered flaws in a … More →
newswww.helpnetsecurity.comOct 13, 2020, 7:32 PM - Adobe addresses a critical security flaw in Adobe Flash PlayerSecurity Affairs
Adobe has released a security update to address a critical remote code execution flaw in Adobe Flash Player that could be easily exploited by hackers. Adobe has released a security update to address a critical remote code execution flaw in Adobe Flash Player (CVE-2020-9746) that could be exploited by threat actors by tricking the victims […]
newssecurityaffairs.comOct 13, 2020, 4:50 PM Adobe has patched a critical arbitrary code execution vulnerability in Flash Player. This is the only flaw fixed by the software giant this Patch Tuesday. The vulnerability, tracked as CVE-2020-9746, has been described as a NULL pointer dereference issue.
newswww.securityweek.comOct 13, 2020, 4:01 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2020-9633CVSS 9.8 · Critical
Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Expl…
- CVE-2020-3757CVSS 8.8 · High
Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful expl…
- CVE-2019-8075CVSS 7.5 · High
Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the cont…
- CVE-2019-8070CVSS 9.8 · Critical
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could lead to Arbitrary Code Execu…
- CVE-2019-8069CVSS 9.8 · Critical
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitr…
- CVE-2019-7845CVSS 8.8 · High
Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successful exploitation could lead to…