Vulnerability CVE-2015-0336


Published: 2015-03-13

Description:
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.

See advisories in our WLB2 database:
Topic
Author
Date
High
Adobe Flash Player NetConnection Type Confusion
Juan vazquez
07.05.2015

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Adobe -> Flash player 

 References:
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00016.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00017.html
http://rhn.redhat.com/errata/RHSA-2015-0697.html
http://www.securityfocus.com/bid/73084
http://www.securitytracker.com/id/1031922
https://helpx.adobe.com/security/products/flash-player/apsb15-05.html
https://security.gentoo.org/glsa/201503-09
https://www.exploit-db.com/exploits/36962/

Copyright 2024, cxsecurity.com

 

Back to Top