Lucene search

K
cve[email protected]CVE-2015-7637
HistoryOct 18, 2015 - 10:59 a.m.

CVE-2015-7637

2015-10-1810:59:07
web.nvd.nist.gov
34
cve-2015-7637
use-after-free
adobe flash player
adobe air
arbitrary code execution
security vulnerability
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.032

Percentile

91.2%

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-7629, CVE-2015-7631, CVE-2015-7635, CVE-2015-7636, CVE-2015-7638, CVE-2015-7639, CVE-2015-7640, CVE-2015-7641, CVE-2015-7642, CVE-2015-7643, and CVE-2015-7644.

Affected configurations

NVD
Node
adobeflash_playerRange11.2.202.521
AND
linuxlinux_kernelMatch-
Node
adobeairRange19.0.0.190
AND
googleandroid
Node
adobeairRange19.0.0.190
OR
adobeair_sdkRange19.0.0.190
OR
adobeair_sdk_\&_compilerRange19.0.0.190
AND
applemac_os_xMatch-
OR
microsoftwindowsMatch-
Node
adobeflash_playerRange19.0.0.185
AND
applemac_os_xMatch-
OR
microsoftwindowsMatch-
VendorProductVersionCPE
adobeflash_playercpe:/a:adobe:flash_player::::

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.032

Percentile

91.2%