Use-After-Free Vulnerability in Adobe Flash Player and Adobe AIR
CVE-2015-8647

8.8HIGH

Key Information:

Vendor
Adobe
Status
Vendor
CVE Published:
28 December 2015

Summary

A use-after-free vulnerability is present in several versions of Adobe Flash Player and Adobe AIR, which could allow an attacker to execute arbitrary code due to improper handling of memory. This flaw can be exploited through various unspecified vectors, potentially compromising the security of affected systems across different platforms like Windows and OS X, as well as on Linux environments.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.