10
CVSSv2

CVE-2015-8410

Published: 10/12/2015 Updated: 10/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in Adobe Flash Player prior to 18.0.0.268 and 19.x and 20.x prior to 20.0.0.228 on Windows and OS X and prior to 11.2.202.554 on Linux, Adobe AIR prior to 20.0.0.204, Adobe AIR SDK prior to 20.0.0.204, and Adobe AIR SDK & Compiler prior to 20.0.0.204 allows malicious users to execute arbitrary code via unspecified vectors, a different vulnerability thanand CVE-2015-8454.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player 19.0.0.185

adobe flash_player

adobe flash_player 19.0.0.226

adobe flash_player 19.0.0.207

adobe flash_player 19.0.0.245

adobe air_sdk_\\&_compiler

adobe air_sdk

adobe air

Vendor Advisories

Synopsis Critical: flash-plugin security update Type/Severity Security Advisory: Critical Topic An updated Adobe Flash Player package that fixes multiple security issuesis now available for Red Hat Enterprise Linux 5 and 6 SupplementaryRed Hat Product Security has rated this update as having Critical secur ...

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=593 There is a use-after-free in MovieClipattachBitmap If the depth parameter is an object with valueOf defined, this method can free the MovieClip, which is then used A minimal PoC follows: thiscreateEmptyMovieClip("mc", 1); var b = new flashdisplayBitmapData(100, ...