CVE-2015-8658 Information

Description

Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux Adobe AIR before 20.0.0.204 Adobe AIR SDK before 20.0.0.204 and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (uninitialized pointer dereference and memory corruption) via crafted MPEG-4 data a different vulnerability than CVE-2015-8045 CVE-2015-8047 CVE-2015-8060 CVE-2015-8408 CVE-2015-8416 CVE-2015-8417 CVE-2015-8418 CVE-2015-8419 CVE-2015-8443 CVE-2015-8444 CVE-2015-8451 CVE-2015-8455 CVE-2015-8652 CVE-2015-8654 CVE-2015-8656 CVE-2015-8657 and CVE-2015-8820.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Reference

http://www.securityfocus.com/bid/84160 http://www.zerodayinitiative.com/advisories/ZDI-15-662 https://helpx.adobe.com/security/products/flash-player/apsb15-32.html

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: