← Back

CVE-2015-3091

nvd nist
Published: May 13, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-3092.

Affected (21)

4 products
Flash Player
Air
Air Sdk
Air Sdk & Compiler
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 11.2.202.475
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Configuration B
17 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Adobe
Up to 13.0.0.264
Version 14.0.0.125
Version 14.0.0.145
Version 14.0.0.176
Version 14.0.0.179
Version 15.0.0.152
Version 15.0.0.167
Version 15.0.0.189
Version 15.0.0.223
Version 15.0.0.239
Version 15.0.0.246
Version 16.0.0.235
Version 16.0.0.257
Version 16.0.0.287
Version 16.0.0.296
Version 17.0.0.134
Version 17.0.0.169
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Microsoft
Windows
All versions
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Up to 17.0.0.144
Up to 17.0.0.144
Up to 17.0.0.144

References (16)

Timeline

No history available yet.