10
CVE-2015-0348
- EPSS 8.76%
- Veröffentlicht 14.04.2015 22:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Buffer overflow in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Desktop Supplementary Version 5.0
Redhat ≫ Enterprise Linux Desktop Supplementary Version 6.0
Redhat ≫ Enterprise Linux Server Supplementary Version 5.0
Redhat ≫ Enterprise Linux Server Supplementary Version 6.0
Redhat ≫ Enterprise Linux Server Supplementary Eus Version 6.6.z
Redhat ≫ Enterprise Linux Workstation Supplementary Version 6.0
Adobe ≫ Flash Player Version <= 11.2.202.451
Suse ≫ Suse Linux Enterprise Desktop Version 11.0 Update sp3
Suse ≫ Suse Linux Enterprise Desktop Version 12.0
Suse ≫ Suse Linux Workstation Extension Version 12.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.76% | 0.945 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.html
http://rhn.redhat.com/errata/RHSA-2015-0813.html
http://www.securitytracker.com/id/1032105
https://helpx.adobe.com/security/products/flash-player/apsb15-06.html
https://security.gentoo.org/glsa/201504-07