5
CVSSv2

CVE-2015-3040

Published: 14/04/2015 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Adobe Flash Player prior to 13.0.0.281 and 14.x up to and including 17.x prior to 17.0.0.169 on Windows and OS X and prior to 11.2.202.457 on Linux does not properly restrict discovery of memory addresses, which allows malicious users to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-0357.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux desktop supplementary 5.0

redhat enterprise linux workstation supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux server supplementary eus 6.6.z

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 5.0

adobe flash_player

opensuse opensuse 13.1

opensuse opensuse 13.2

suse suse linux workstation extension 12.0

suse suse linux enterprise desktop 12.0

suse suse linux enterprise desktop 11.0

adobe flash_player 14.0.0.125

adobe flash_player 14.0.0.145

adobe flash_player 15.0.0.246

adobe flash_player 16.0.0.235

adobe flash_player 14.0.0.176

adobe flash_player 14.0.0.179

adobe flash_player 16.0.0.257

adobe flash_player 16.0.0.287

adobe flash_player 15.0.0.152

adobe flash_player 15.0.0.167

adobe flash_player 16.0.0.296

adobe flash_player 17.0.0.134

adobe flash_player 15.0.0.189

adobe flash_player 15.0.0.223

adobe flash_player 15.0.0.239

Vendor Advisories

Adobe Flash Player before 1300281 and 14x through 17x before 1700169 on Windows and OS X and before 112202457 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-0357 ...