Vulnerability Name: | CVE-2015-7647 (CCN-107223) | ||||||||||||||||||||
Assigned: | 2015-10-14 | ||||||||||||||||||||
Published: | 2015-10-14 | ||||||||||||||||||||
Updated: | 2017-09-13 | ||||||||||||||||||||
Summary: | Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7648. CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') | ||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: CCN Type: Ars Technica Web site New zero-day exploit hits fully patched Adobe Flash [Updated] Source: MITRE Type: CNA CVE-2015-7647 Source: CCN Type: Google Chrome Releases Web site Stable Channel Refresh Source: REDHAT Type: UNKNOWN RHSA-2015:1913 Source: REDHAT Type: UNKNOWN RHSA-2015:2024 Source: BID Type: UNKNOWN 77115 Source: CCN Type: BID-77115 Adobe Flash Player CVE-2015-7647 Unspecified Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1033850 Source: XF Type: UNKNOWN adobe-flash-cve20157647-code-exec(107223) Source: CCN Type: Adobe Security Bulletin APSA15-05 Security Advisory for Adobe Flash Player Source: CCN Type: Adobe Security Bulletin APSA15-27 Security updates available for Adobe Flash Player Source: CONFIRM Type: Patch, Vendor Advisory https://helpx.adobe.com/security/products/flash-player/apsb15-27.html Source: CCN Type: Packet Storm Security [12-14-2015] Adobe Flash IExternalizable.readExternal Type Confusion Source: GENTOO Type: UNKNOWN GLSA-201511-02 Source: CCN Type: Microsoft Security Advisory 2755801 Update for Vulnerabilities in Adobe Flash Player in Internet Explorer Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [12-14-2015] Source: EXPLOIT-DB Type: UNKNOWN 38969 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-7647 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |