10

CVE-2015-3088

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version <= 11.2.202.475
   Linux ≫ Linux Kernel Version -
Adobe ≫ Flash Player Version <= 13.0.0.264
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 14.0.0.125
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 14.0.0.145
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 14.0.0.176
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 14.0.0.179
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 15.0.0.152
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 15.0.0.167
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 15.0.0.189
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 15.0.0.223
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 15.0.0.239
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 15.0.0.246
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 16.0.0.235
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 16.0.0.257
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 16.0.0.287
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 16.0.0.296
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 17.0.0.134
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version 17.0.0.169
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Air Version <= 17.0.0.144
Adobe ≫ Air Sdk Version <= 17.0.0.144
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 61.98% 0.991
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.html
https://security.gentoo.org/glsa/201505-02
http://rhn.redhat.com/errata/RHSA-2015-1005.html
http://www.securitytracker.com/id/1032285
https://helpx.adobe.com/security/products/flash-player/apsb15-09.html
Patch
Vendor Advisory
http://www.securityfocus.com/bid/74609
https://www.exploit-db.com/exploits/37844/