← Back

CVE-2015-3097

nvd nist
Published: Jun 10, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by predicting this address.

Affected (22)

4 products
Air
Air Sdk
Air Sdk & Compiler
Flash Player
1 product
Windows 7
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Up to 17.0.0.172
Up to 17.0.0.172
Up to 17.0.0.172
Adobe
Up to 13.0.0.289
Version 14.0.0.125
Version 14.0.0.145
Version 14.0.0.176
Version 14.0.0.179
Version 15.0.0.152
Version 15.0.0.167
Version 15.0.0.189
Version 15.0.0.223
Version 15.0.0.239
Version 15.0.0.246
Version 16.0.0.235
Version 16.0.0.257
Version 16.0.0.287
Version 16.0.0.296
Version 17.0.0.134
Version 17.0.0.169
Version 17.0.0.188
All versions

References (12)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.