4.3

CVE-2015-3081

Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to bypass the Internet Explorer Protected Mode protection mechanism via unspecified vectors.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeFlash Player Version <= 11.2.202.475
   LinuxLinux Kernel Version-
AdobeAir Version <= 17.0.0.144
AdobeAir Sdk Version <= 17.0.0.144
AdobeFlash Player Version <= 13.0.0.264
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version14.0.0.125
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version14.0.0.145
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version14.0.0.176
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version14.0.0.179
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.152
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.167
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.189
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.223
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.239
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.246
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version16.0.0.235
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version16.0.0.257
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version16.0.0.287
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version16.0.0.296
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version17.0.0.134
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version17.0.0.169
   ApplemacOS X Version-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.78% 0.916
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.