10
CVSSv2

CVE-2015-5568

Published: 22/09/2015 Updated: 17/02/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe Flash Player prior to 18.0.0.241 and 19.x prior to 19.0.0.185 on Windows and OS X and prior to 11.2.202.521 on Linux, Adobe AIR prior to 19.0.0.190, Adobe AIR SDK prior to 19.0.0.190, and Adobe AIR SDK & Compiler prior to 19.0.0.190 allow malicious users to cause a denial of service (vector-length corruption) or possibly have unspecified other impact via unknown vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe flash_player 14.0.0.125

adobe flash_player 15.0.0.223

adobe flash_player 15.0.0.239

adobe flash_player 17.0.0.188

adobe flash_player 17.0.0.190

adobe flash_player 14.0.0.179

adobe flash_player 15.0.0.152

adobe flash_player 16.0.0.257

adobe flash_player 16.0.0.287

adobe flash_player 18.0.0.194

adobe flash_player 18.0.0.203

adobe flash_player 14.0.0.145

adobe flash_player 14.0.0.176

adobe flash_player 15.0.0.246

adobe flash_player 16.0.0.235

adobe flash_player 17.0.0.191

adobe flash_player 18.0.0.160

adobe flash_player 15.0.0.167

adobe flash_player 15.0.0.189

adobe flash_player 16.0.0.296

adobe flash_player 17.0.0.134

adobe flash_player 17.0.0.169

adobe flash_player 18.0.0.209

adobe flash_player 18.0.0.232

adobe air_sdk_\\&_compiler

adobe air_sdk

adobe air

google android

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=504 The latest version of the Vector<primitive> length check in Flash 18,0,0,232 is not robust against memory corruptions such as heap overflows While it’s no longer possible to obviously bypass the length check there’s still unguarded data in the object which ...