10
CVSSv2

CVE-2015-5117

Published: 09/07/2015 Updated: 22/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in Adobe Flash Player prior to 13.0.0.302 and 14.x up to and including 18.x prior to 18.0.0.203 on Windows and OS X and prior to 11.2.202.481 on Linux, Adobe AIR prior to 18.0.0.180, Adobe AIR SDK prior to 18.0.0.180, and Adobe AIR SDK & Compiler prior to 18.0.0.180 allows malicious users to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3124, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3131, CVE-2015-3132, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, and CVE-2015-4430.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe air

adobe air sdk \\& compiler

adobe air sdk

adobe flash_player 14.0.0.125

adobe flash_player 14.0.0.145

adobe flash_player 15.0.0.246

adobe flash_player 16.0.0.235

adobe flash_player 17.0.0.190

adobe flash_player 15.0.0.223

adobe flash_player 15.0.0.239

adobe flash_player 17.0.0.169

adobe flash_player 17.0.0.188

adobe flash_player 15.0.0.167

adobe flash_player 15.0.0.189

adobe flash_player 16.0.0.296

adobe flash_player 17.0.0.134

adobe flash_player 18.0.0.160

adobe flash_player 14.0.0.176

adobe flash_player 14.0.0.179

adobe flash_player 15.0.0.152

adobe flash_player 16.0.0.257

adobe flash_player 16.0.0.287

adobe flash_player 18.0.0.194

Vendor Advisories

Use-after-free vulnerability in Adobe Flash Player before 1300302 and 14x through 18x before 1800203 on Windows and OS X and before 112202481 on Linux, Adobe AIR before 1800180, Adobe AIR SDK before 1800180, and Adobe AIR SDK & Compiler before 1800180 allows attackers to execute arbitrary code via unspecified vectors, a diff ...