10
CVSSv2

CVE-2015-5550

Published: 14/08/2015 Updated: 05/01/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in Adobe Flash Player prior to 18.0.0.232 on Windows and OS X and prior to 11.2.202.508 on Linux, Adobe AIR prior to 18.0.0.199, Adobe AIR SDK prior to 18.0.0.199, and Adobe AIR SDK & Compiler prior to 18.0.0.199 allows malicious users to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe air sdk \\& compiler

adobe air sdk

adobe air

Vendor Advisories

Use-after-free vulnerability in Adobe Flash Player before 1800232 on Windows and OS X and before 112202508 on Linux, Adobe AIR before 1800199, Adobe AIR SDK before 1800199, and Adobe AIR SDK & Compiler before 1800199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, ...

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=403&can=1&q=label%3AProduct-Flash%20modified-after%3A2015%2F8%2F17&sort=id There is a use-after-free in MovieClipswapDepths, a POC is as follows: var clip1 = thiscreateEmptyMovieClip("clip1", 1); var clip2 = thiscreateEmptyMovieClip("clip2", 2); var n = {v ...