5

CVE-2015-7628

Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
AdobeFlash Player Version <= 19.0.0.185
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeAir Version <= 19.0.0.190
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeAir Sdk Version <= 19.0.0.190
   ApplemacOS X Version-
   MicrosoftWindows Version-
AdobeFlash Player Version <= 11.2.202.521
   LinuxLinux Kernel Version-
AdobeAir Version <= 19.0.0.190
   GoogleAndroid
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.39% 0.795
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.