PT-2020-20735 · Adobe+1 · Flash Player+1

Published

2020-10-13

·

Updated

2025-01-24

·

CVE-2020-9746

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions 32.0.0.433 and earlier
Description The issue is a NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL.
Recommendations For Adobe Flash Player versions 32.0.0.433 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2020-9746
MGASA-2020-0386
RHSA-2020:4251
RHSA-2020_4251

Affected Products

Flash Player
Red Hat