Lucene search

K
cveAdobeCVE-2015-4435
HistoryJul 15, 2015 - 2:59 p.m.

CVE-2015-4435

2015-07-1514:59:04
adobe
web.nvd.nist.gov
47
cve-2015-4435
adobe
reader
acrobat
javascript
api
execution
restrictions
vulnerability
windows
os x

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.02

Percentile

88.9%

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4447, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.

Affected configurations

Nvd
Node
adobeacrobatRange10.010.1.14
OR
adobeacrobatRange11.0.011.0.11
OR
adobeacrobat_readerRange10.010.1.14
OR
adobeacrobat_readerRange11.0.011.0.11
AND
applemacosMatch-
OR
microsoftwindowsMatch-
Node
adobeacrobat_dcRange15.006.3003315.006.30060classic
OR
adobeacrobat_dcRange15.007.2003315.008.20082continuous
OR
adobeacrobat_reader_dcRange15.006.3003315.006.30060classic
OR
adobeacrobat_reader_dcRange15.007.2003315.008.20082continuous
AND
applemacosMatch-
OR
microsoftwindowsMatch-
VendorProductVersionCPE
adobeacrobat*cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
adobeacrobat_reader*cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
applemacos-cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
adobeacrobat_dc*cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*
adobeacrobat_dc*cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
adobeacrobat_reader_dc*cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*
adobeacrobat_reader_dc*cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.02

Percentile

88.9%