Lucene search

K
nessusTenable9042.PRM
HistoryJan 08, 2016 - 12:00 a.m.

Adobe AIR < 19.0.0.241 Multiple Vulnerabilities (APSB15-28)

2016-01-0800:00:00
Tenable
www.tenable.com
17

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.906

Percentile

98.9%

Versions of Adobe AIR prior to 19.0.0.241 are outdated and thus unpatched for the following vulnerabilities :

  • A type confusion error exists that allows an attacker to execute arbitrary code. (CVE-2015-7659)
  • A security bypass vulnerability exists that allows an attacker to write arbitrary data to the file system under user permissions. (CVE-2015-7662)
  • Multiple use-after-free vulnerabilities exist that allow an attacker to execute arbitrary code. (CVE-2015-7651, CVE-2015-7652, CVE-2015-7653, CVE-2015-7654, CVE-2015-7655, CVE-2015-7656, CVE-2015-7657, CVE-2015-7658, CVE-2015-7660, CVE-2015-7661, CVE-2015-7663, CVE-2015-8042, CVE-2015-8043, CVE-2015-8044, CVE-2015-8046)
Binary data 9042.prm

References

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.906

Percentile

98.9%