5

CVE-2015-3108

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
AdobeFlash Player Version <= 11.2.202.460
   LinuxLinux Kernel Version-
AdobeAir Version <= 17.0.0.144
AdobeAir Version <= 17.0.0.172
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeAir Sdk Version <= 17.0.0.172
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version <= 13.0.0.289
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version14.0.0.125
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version14.0.0.145
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version14.0.0.176
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version14.0.0.179
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.152
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.167
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.189
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.223
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.239
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version15.0.0.246
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version16.0.0.235
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version16.0.0.257
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version16.0.0.287
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version16.0.0.296
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version17.0.0.134
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version17.0.0.169
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version17.0.0.188
   ApplemacOS X Version-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.44% 0.623
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.