10
CVE-2015-3043
- EPSS 74.45%
- Veröffentlicht 14.04.2015 22:59:21
- Zuletzt bearbeitet 21.04.2026 21:09:08
- Erkennungen
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version < 11.2.202.457
Adobe ≫ Flash Player Version >= 14.0.0.125 < 17.0.0.169
Novell ≫ Suse Linux Enterprise Desktop Version 11.0 Update sp3
Novell ≫ Suse Linux Enterprise Desktop Version 12.0
Novell ≫ Suse Linux Enterprise Workstation Extension Version 12.0
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 6.6
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Aus Version 6.6
Redhat ≫ Enterprise Linux Server From Rhui Version 5.0
Redhat ≫ Enterprise Linux Server From Rhui Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Adobe Flash Player Memory Corruption Vulnerability
SchwachstelleA memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
BeschreibungThe impacted product is end-of-life and should be disconnected if still in use.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 74.45% | 0.994 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.html
http://rhn.redhat.com/errata/RHSA-2015-0813.html
http://www.securitytracker.com/id/1032105
https://helpx.adobe.com/security/products/flash-player/apsb15-06.html
https://security.gentoo.org/glsa/201504-07
http://www.securityfocus.com/bid/74062
https://www.exploit-db.com/exploits/37536/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3043
https://github.com/cisagov/vulnrichment/issues/196