5

CVE-2015-3097

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by predicting this address.

Data is provided by the National Vulnerability Database (NVD)
AdobeAir Version <= 17.0.0.172
AdobeAir Sdk Version <= 17.0.0.172
AdobeFlash Player Version <= 13.0.0.289
AdobeFlash Player Version14.0.0.125
AdobeFlash Player Version14.0.0.145
AdobeFlash Player Version14.0.0.176
AdobeFlash Player Version14.0.0.179
AdobeFlash Player Version15.0.0.152
AdobeFlash Player Version15.0.0.167
AdobeFlash Player Version15.0.0.189
AdobeFlash Player Version15.0.0.223
AdobeFlash Player Version15.0.0.239
AdobeFlash Player Version15.0.0.246
AdobeFlash Player Version16.0.0.235
AdobeFlash Player Version16.0.0.257
AdobeFlash Player Version16.0.0.287
AdobeFlash Player Version16.0.0.296
AdobeFlash Player Version17.0.0.134
AdobeFlash Player Version17.0.0.169
AdobeFlash Player Version17.0.0.188
MicrosoftWindows 7 HwPlatformx64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.22% 0.924
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.