Vulnerability Name: | CVE-2015-8457 (CCN-108901) | ||||||||||||||||
Assigned: | 2015-12-08 | ||||||||||||||||
Published: | 2015-12-08 | ||||||||||||||||
Updated: | 2017-02-17 | ||||||||||||||||
Summary: | Stack-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8407. | ||||||||||||||||
CVSS v3 Severity: | 8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8457 Source: CCN Type: Google Chrome Releases Web site Stable Channel Refresh Source: BID Type: UNKNOWN 78802 Source: CCN Type: BID-78802 Adobe Flash Player and AIR APSB15-32 Remote Code Execution and Stack Buffer Overflow Vulnerabilities Source: SECTRACK Type: UNKNOWN 1034318 Source: MISC Type: UNKNOWN http://www.zerodayinitiative.com/advisories/ZDI-15-636 Source: XF Type: UNKNOWN adobe-flash-cve20158457-bo(108901) Source: CONFIRM Type: UNKNOWN https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388 Source: CONFIRM Type: UNKNOWN https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680 Source: CONFIRM Type: UNKNOWN https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Source: CCN Type: Adobe Security Bulletin APSB15-32 Security updates available for Adobe Flash Player Source: CONFIRM Type: Patch, Vendor Advisory https://helpx.adobe.com/security/products/flash-player/apsb15-32.html Source: CCN Type: Microsoft Security Advisory 2755801 Update for Vulnerabilities in Adobe Flash Player in Internet Explorer Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8457 Source: CCN Type: ZDI-15-636 Adobe Flash HLS Stack Buffer Overflow Remote Code Execution Vulnerability | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |