10
CVSSv2

CVE-2015-5558

Published: 14/08/2015 Updated: 05/01/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe Flash Player prior to 18.0.0.232 on Windows and OS X and prior to 11.2.202.508 on Linux, Adobe AIR prior to 18.0.0.199, Adobe AIR SDK prior to 18.0.0.199, and Adobe AIR SDK & Compiler prior to 18.0.0.199 allow malicious users to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-5554, CVE-2015-5555, and CVE-2015-5562.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe air sdk \\& compiler

adobe air sdk

adobe air

Vendor Advisories

Adobe Flash Player before 1800232 on Windows and OS X and before 112202508 on Linux, Adobe AIR before 1800199, Adobe AIR SDK before 1800199, and Adobe AIR SDK & Compiler before 1800199 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-5554, CVE-2015-55 ...

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=422&can=1&q=label%3AProduct-Flash%20modified-after%3A2015%2F8%2F17&sort=id There is a type confusion issue in the TextFormat constructor that is reachable because the FileReference constructor does not verify that the incoming object is of type Object (it only ...