10
CVSSv2

CVE-2015-7647

Published: 18/10/2015 Updated: 13/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe Flash Player prior to 18.0.0.255 and 19.x prior to 19.0.0.226 on Windows and OS X and prior to 11.2.202.540 on Linux allows malicious users to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7648.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

Vendor Advisories

Adobe Flash Player before 1800255 and 19x before 1900226 on Windows and OS X and before 112202540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7648 ...

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=548 If IExternalizablereadExternal is overridden with a value that is not a function, Flash assumes it is a function even though it is not one This leads to execution of a 'method' outside of the ActionScript object's ActionScript vtable, leading to memory corruption A ...